{"id":"CVE-2017-14735","details":"OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of &colon; to construct a javascript: URL.","aliases":["GHSA-q44v-xc3g-v7jq"],"modified":"2026-07-08T10:55:20.483427Z","published":"2017-09-25T21:29:01.147Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/105656"},{"type":"WEB","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"REPORT","url":"https://github.com/nahsra/antisamy/issues/10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nahsra/antisamy","events":[{"introduced":"0"},{"fixed":"e76f02a77afb4e43b897f13d17b5bc1260b8afde"}],"database_specific":{"cpe":"cpe:2.3:a:antisamy_project:antisamy:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.7"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14735.json","vanir_signatures_modified":"2026-07-08T10:55:20Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/e76f02a77afb4e43b897f13d17b5bc1260b8afde","target":{"function":"getAllowedRegexp3","file":"src/main/java/org/owasp/validator/html/Policy.java"},"deprecated":false,"digest":{"function_hash":"38296343665256146800925089512624014727","length":684},"id":"CVE-2017-14735-89145a1f","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"76597168863106377542647729149058117795","length":759},"id":"CVE-2017-14735-8d573449","signature_type":"Function","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/e76f02a77afb4e43b897f13d17b5bc1260b8afde","target":{"file":"src/main/java/org/owasp/validator/html/Policy.java","function":"getAllowedRegexps2"}},{"signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/e76f02a77afb4e43b897f13d17b5bc1260b8afde","target":{"file":"src/main/java/org/owasp/validator/html/Policy.java","function":"getAllowedRegexps"},"deprecated":false,"digest":{"length":468,"function_hash":"167713688936496554436135219004778559751"},"id":"CVE-2017-14735-8e1b45c1","signature_type":"Function"},{"id":"CVE-2017-14735-ce6619a3","signature_type":"Line","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/e76f02a77afb4e43b897f13d17b5bc1260b8afde","target":{"file":"src/test/java/org/owasp/validator/html/test/AntiSamyTest.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["242531706664678322907281439899221657676","322691654413139166161554642784435458311","228770665606969391725818882221754407565"]}},{"deprecated":false,"digest":{"line_hashes":["271525121681651893513839874238978229753","18675375935326488206589624885872683268","102603548094287090460624544441835130286","41577185623837350039340829383570385626","310904760357819484382505909129259233694","51346120417515236278405513067204420577","17406302407210611452030258004537583234","56778795395865919091385706337229722504","316638454160605210019617571828174260255","107525156843728149306753171115678345524","14338240203206133259523620347968423897","283506607799821166973776225566955992840","46414615038259352784909742382973281284","6367814173963641991548439279134737768","328413022229623117742666725410465050829","177210424874647179974513469347005037185","227499033979104965914267531684915421522","317753652799255677328116778938022739424","91966842981012729468032373849709212680","274401988018137917952926441252139022300","245751105935388936167307621259283780701","87310882647633789524284397786924814989","15110741443156493075848407544006614224"],"threshold":0.9},"id":"CVE-2017-14735-e9081517","signature_type":"Line","signature_version":"v1","source":"https://github.com/nahsra/antisamy/commit/e76f02a77afb4e43b897f13d17b5bc1260b8afde","target":{"file":"src/main/java/org/owasp/validator/html/Policy.java"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}