VDB
KO
MEDIUM 4.7

GHSA-pmhh-3w7g-xqp8

jsoup: Cleaner may expose markup with custom raw-text elements

Quick fix

GHSA-pmhh-3w7g-xqp8 — org.jsoup:jsoup: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.23.1</version> for org.jsoup:jsoup

Details

When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup after serialization and potentially allowing XSS.

jsoup’s built-in Safelists are unaffected.

## Patches

Upgrade to jsoup 1.23.1.

## Workarounds

Until upgrading, do not permit raw-text elements in custom Safelists used to clean untrusted HTML.

## Additional security considerations

This fix addresses malformed tag-name handling only.

Permitting raw-text elements in a custom `Safelist` does not make their contents inherently safe. For example, applications that permit `style` must apply appropriate CSS safeguards separately, because jsoup does not parse or sanitize CSS.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.jsoup:jsoup
Introduced in: 1.14.3 Fixed in: 1.23.1
Fix # pom.xml: bump <version>1.23.1</version> for org.jsoup:jsoup

References