CVE-2021-42575
9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.98% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-10-18 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| oracle | middleware common libraries and tools |
| oracle | primavera unifier |
| owasp | java html sanitizer |
References
- https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
→ the Explorer · watch your stack · NVD