CVE-2017-15717
Cross-site Scripting in Apache Sling XSS Protection API
6.1
MEDIUM
CVSS 3.1
EPSS 1.6%
Description
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.
How to fix CVE-2017-15717
To remediate CVE-2017-15717, upgrade the affected package to a fixed version below.
- —upgrade to 2.0.4 or later
- —no fix listed
Is CVE-2017-15717 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 1.0.4, < 2.0.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |