CVE-2022-32533

CVE-2022-32533: Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues

Vendor Apache Software Foundation
Product Apache Portals
Weakness CWE-79 · XSS
Published July 6, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

Description

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

Key dates

Disclosure timeline

July 6, 2022 CVE published
August 3, 2024 Record updated