Back to search
CVE-2022-32533
Published: Jul 6, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Portals | affected Jetspeed 2.3.1 |
Weaknesses (CWE)
References
https://lists.apache.org/thread/d3g248pr03x8rvmh8p2t3xdlw0wn5dz2
x_refsource_MISC
https://www.openwall.com/lists/oss-security/2022/07/06/1
x_refsource_MISC
[oss-security] 20220706 CVE-2022-32533: Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now