CVE-2022-32533 is a critical vulnerability affecting Apache Jetspeed-2, stemming from insufficient filtering of untrusted user input. This flaw can lead to multiple attack types, including XSS, CSRF, XXE, and SSRF, with a CVSS score of 9.8 (CRITICAL) indicating high impact on confidentiality, integrity, and availability. While a configuration change ("xss.filter.post = true") might offer mitigation, Apache Jetspeed is a dormant project, meaning no official updates will be released. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0CPE matchmatch criteria | cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.