{"id":"GHSA-pcm9-fp55-563v","summary":"OWASP HTML Sanitizer allows redirecting to an arbitrary URL when JavaScript is disabled","details":"OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element. ","aliases":["CVE-2011-4457"],"modified":"2024-12-02T05:41:41.690237Z","published":"2022-05-17T05:36:48Z","database_specific":{"nvd_published_at":"2011-11-17T23:55:00Z","cwe_ids":["CWE-200"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-01-19T17:48:40Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4457"},{"type":"WEB","url":"https://github.com/OWASP/java-html-sanitizer/commit/2027d3df73f62eb30b7f08269f346989f03144bd"},{"type":"PACKAGE","url":"https://github.com/OWASP/java-html-sanitizer"},{"type":"WEB","url":"https://github.com/OWASP/java-html-sanitizer/blob/35c506cfd452dba634202f13a7cc2e2a63ad7ee0/change_log.md?plain=1#L103"},{"type":"WEB","url":"https://github.com/OWASP/java-html-sanitizer/blob/35c506cfd452dba634202f13a7cc2e2a63ad7ee0/docs/cve20114457.md"},{"type":"WEB","url":"http://code.google.com/p/owasp-java-html-sanitizer/wiki/CVE20114457"},{"type":"WEB","url":"http://owasp-java-html-sanitizer.googlecode.com/svn/trunk/CHANGE_LOG.html"}],"affected":[{"package":{"name":"com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer","ecosystem":"Maven","purl":"pkg:maven/com.googlecode.owasp-java-html-sanitizer/owasp-java-html-sanitizer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"88"}]}],"versions":["1.1","r136","r156","r163","r164","r173","r198","r209","r223","r232","r239"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pcm9-fp55-563v/GHSA-pcm9-fp55-563v.json"}}],"schema_version":"1.9.0"}