OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.mikesamuel:json-sanitizer(Maven) | 0 | 1.2.2 | N/A |
CVSS Metrics