CVE-2022-32533

CVE-2022-32533: Apache Portals Jetspeed XSS, CSRF, SSRF, and XXE issues

Vendor Apache Software Foundation
Product Apache Portals
Weakness CWE-79 · XSS
Published July 6, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

Key dates

02Disclosure timeline

July 6, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE