{"id":"GHSA-3w73-fmf3-hg5c","summary":"Policies not properly enforced in OWASP Java HTML Sanitizer","details":"The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the `SELECT`, `STYLE`, and `OPTION` elements.","aliases":["CVE-2021-42575"],"modified":"2024-02-19T05:33:53.630019Z","published":"2021-10-19T20:15:50Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-10-19T16:10:40Z","nvd_published_at":"2021-10-18T15:15:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42575"},{"type":"WEB","url":"https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"affected":[{"package":{"name":"com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20211018.1"}]}],"versions":["1.1","20150501.1","20151202.2","20160203.1","20160413.1","20160422.1","20160526.1","20160614.1","20160628.1","20160827.1","20160924.1","20170329.1","20170408.1","20170411.1","20170512.1","20170515.1","20171016.1","20180219.1","20181114.1","20190325.1","20190503.1","20190610.1","20191001.1","20200615.1","20200713.1","r136","r156","r163","r164","r173","r198","r209","r223","r232","r239"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-3w73-fmf3-hg5c/GHSA-3w73-fmf3-hg5c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}