← Back to browse · API

CVE-2022-32533

Severity
CRITICAL
CVSS
9.8
EPSS
0.03881
Risk score
40.56
CISA KEV
No
PoC
No
Published
2022-07-06
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-6346, GHSA-H975-R69H-4W9P
Products
Apache Software Foundation:Apache Portals Jetspeed 2.3.1
Sources
euvd EUVD-2022-6346

Description

Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue

References