Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7753

Опубликовано: 07 мар. 2018
Источник: debian

Описание

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-bleachfixed2.1.3-1package
python-bleachnot-affectedstretchpackage
python-bleachnot-affectedjessiepackage

Примечания

  • https://github.com/mozilla/bleach/pull/356

  • https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
nvd
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
github
около 7 лет назад

Bleach URI Scheme Restriction Bypass