Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7753

Опубликовано: 07 мар. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mozilla:bleach:2.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bleach:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:bleach:2.1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00511
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
debian
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that ...

CVSS3: 9.8
github
около 7 лет назад

Bleach URI Scheme Restriction Bypass

EPSS

Процентиль: 66%
0.00511
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20