Vulnerability Details CVE-2022-32533
Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of Apache Portals and no updates will be provided for this issue
Exploit prediction scoring system (EPSS) score
EPSS Score 0.116
EPSS Ranking 93.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-32533
-
cpe:2.3:a:apache:jetspeed:2.2.0
-
cpe:2.3:a:apache:jetspeed:2.2.1
-
cpe:2.3:a:apache:jetspeed:2.2.2
-
cpe:2.3:a:apache:jetspeed:2.3.0
-
cpe:2.3:a:apache:jetspeed:2.3.1