The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer(Maven) | 0 | 20211018.1 | N/A |
CVSS Metrics