CVE Database
/

CVE-2022-32533

Back to search

CVE-2022-32533

Published: Jul 6, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

VendorProductVersions

Apache Software Foundation

Apache Portals

affected
Jetspeed 2.3.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now