peter bassill · operator
$ cve CVE-2021-42575 JSON

CVE-2021-42575

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.98% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploitnone known
Published2021-10-18
Last modified2026-06-17

Affected (3)

VendorProduct
oraclemiddleware common libraries and tools
oracleprimavera unifier
owaspjava html sanitizer

References

→ the Explorer  ·  watch your stack  ·  NVD