CVE-2013-5855: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions
(updated )
This package does not perform appropriate encoding when a <h:outputText>
tag or EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
References
Detect and mitigate CVE-2013-5855 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →