Описание
Security update for python-bleach
This update for python-bleach to version 3.1.1 fixes the following issue:
- Python-bleach was updated to 3.1.1
- CVE-2020-6802: Fixed mutation XSS vulnerabilities (boo#1165303).
Список пакетов
openSUSE Leap 15.1
python2-bleach-3.1.1-lp151.3.6.1
python3-bleach-3.1.1-lp151.3.6.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0308-1
- SUSE Security Ratings
- SUSE Bug 1165303
- SUSE CVE CVE-2020-6802 page
Описание
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
Затронутые продукты
openSUSE Leap 15.1:python2-bleach-3.1.1-lp151.3.6.1
openSUSE Leap 15.1:python3-bleach-3.1.1-lp151.3.6.1
Ссылки
- CVE-2020-6802
- SUSE Bug 1165303