Description
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
Remediation
References
https://github.com/nahsra/antisamy/commit/0199e7e194dba5e7d7197703f43ebe22401e61ae
https://github.com/nahsra/antisamy/releases/tag/v1.6.6
Related Vulnerabilities
CVE-2022-24815 Vulnerability in npm package generator-jhipster
CVE-2021-43787 Vulnerability in npm package nodebb
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk14
CVE-2020-26217 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-21320 Vulnerability in npm package matrix-react-sdk