OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "target": { "file": "src/main/java/org/owasp/validator/html/scan/AntiSamyDOMScanner.java", "function": "processStyleTag" }, "id": "CVE-2022-28367-0b2c0c31", "digest": { "length": 772.0, "function_hash": "126801159696717847423144960297568189815" }, "signature_version": "v1", "source": "https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/test/java/org/owasp/validator/html/test/TestPolicy.java" }, "id": "CVE-2022-28367-25aaeafe", "digest": { "line_hashes": [ "102395914133567038206162999411433682008", "172884204425066366557287973775564351161", "69891993284936710533120018776222880680", "101875443924565134781607355773096569819" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/main/java/org/owasp/validator/html/scan/AntiSamyDOMScanner.java" }, "id": "CVE-2022-28367-7e6bb515", "digest": { "line_hashes": [ "136642796337683393202179711700642177900", "128870773222262935459506770502729513736", "53317207876928769004406313497214808576", "229860542803382738460268100061225296529", "191271951501702959750778219281103334850", "214735603198293884394947938323229844290", "313136713396010417509642112145256498856", "253651523449955296939612244815053890059", "317205302213306631323288053769021199559", "293952431329732310555540089749725023644", "18300821776322308221142286789123141730", "175784914226008108155297247775601230154", "232125387965580752414898968674125482203" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/test/java/org/owasp/validator/html/test/TestPolicy.java", "function": "TestPolicy" }, "id": "CVE-2022-28367-a7cd8a4c", "digest": { "length": 69.0, "function_hash": "159741469509703674260809042637878075557" }, "signature_version": "v1", "source": "https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/test/java/org/owasp/validator/html/test/AntiSamyTest.java" }, "id": "CVE-2022-28367-d51b775e", "digest": { "line_hashes": [ "87017425024504894246560502640970701778", "245016119317914046846709556822679037632" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae" } ] }