Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x95h-979x-cf3j

Опубликовано: 19 окт. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8

Описание

Policies not properly enforced in bluemonday

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Пакеты

Наименование

pybluemonday

pip
Затронутые версииВерсия исправления

< 0.0.8

0.0.8

Наименование

github.com/microcosm-cc/bluemonday

go
Затронутые версииВерсия исправления

< 1.0.16

1.0.16

EPSS

Процентиль: 55%
0.00321
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

CVSS3: 9.8
nvd
больше 4 лет назад

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

CVSS3: 9.8
debian
больше 4 лет назад

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Py ...

EPSS

Процентиль: 55%
0.00321
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20