* UNSUPPORTED WHEN ASSIGNED * Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue.
{ "nvd_published_at": "2022-07-06T10:15:00Z", "github_reviewed_at": "2022-07-08T17:57:13Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-352", "CWE-611", "CWE-79", "CWE-918" ] }