Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9mq-p2f9-cfqv

Опубликовано: 04 янв. 2019
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Bleach URI Scheme Restriction Bypass

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Пакеты

Наименование

bleach

pip
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.3

2.1.3

EPSS

Процентиль: 66%
0.00511
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
nvd
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
debian
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that ...

EPSS

Процентиль: 66%
0.00511
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20