DEBIAN-CVE-2024-23635

Source
https://security-tracker.debian.org/tracker/CVE-2024-23635
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-23635.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-23635
Upstream
Published
2024-02-02T17:15:11Z
Modified
2026-09-15T09:03:01Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the preserveComments directive must be enabled in your policy file. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. Patched in AntiSamy 1.7.5 and later.

References

Affected packages

Debian:12 / libowasp-antisamy-java

Package

Name
libowasp-antisamy-java
Purl
pkg:deb/debian/libowasp-antisamy-java?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.5.3+dfsg-1.1
1.7.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-23635.json"

Debian:13 / libowasp-antisamy-java

Package

Name
libowasp-antisamy-java
Purl
pkg:deb/debian/libowasp-antisamy-java?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-23635.json"

Debian:14 / libowasp-antisamy-java

Package

Name
libowasp-antisamy-java
Purl
pkg:deb/debian/libowasp-antisamy-java?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-23635.json"