CVE-2017-15717
Published Jan 10, 2018A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special craf…
Vendor/product archive
1 CVEs tagged to apache / sling_xss_protection_api — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special craf…