Fedora Account System
Red Hat Associate
Red Hat Customer
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character. Upstream Reference: https://github.com/nahsra/antisamy/releases/tag/v1.6.4 https://github.com/nahsra/antisamy/pull/87
Marking Red Hat JBoss Fuse 6 as having a low impact, this is because although antisamy is present in the offline repository it is not used. This vulnerability is out of security support scope for the following products: * Red Hat JBoss Fuse 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-35043