Description
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
Remediation
References
http://www.securityfocus.com/bid/95101
http://www.securitytracker.com/id/1037532
https://github.com/nahsra/antisamy/issues/2
Related Vulnerabilities
CVE-2020-5207 Vulnerability in maven package io.ktor:ktor-client-cio
CVE-2019-20174 Vulnerability in npm package auth0-lock
CVE-2016-10580 Vulnerability in npm package nodewebkit
CVE-2014-3623 Vulnerability in maven package org.apache.wss4j:wss4j
CVE-2018-9159 Vulnerability in maven package com.sparkjava:spark-core