[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4892-1 python-bleach -- python-bleach

ID: oval:org.secpod.oval:def:605494Date: (C)2021-04-19   (M)2023-03-06
Class: PATCHFamily: unix




It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, "p" or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and "strip_comments=False" is set.

Platform:
Debian 10.x
Product:
python3-bleach
python-bleach
Reference:
DSA-4892-1
CVE-2021-23980
CVE    1
CVE-2021-23980
CPE    2
cpe:/o:debian:debian_linux:10.x
cpe:/a:mozilla:python-bleach

© SecPod Technologies