Описание
Security update for python-markdown2
This update for python-markdown2 fixes the following issues:
- CVE-2020-11888: Fixed unsanitized input for cross-site scripting (boo#1171379)
Список пакетов
openSUSE Leap 15.1
python2-markdown2-2.3.7-lp151.2.3.1
python3-markdown2-2.3.7-lp151.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0651-1
- SUSE Security Ratings
- SUSE Bug 1171379
- SUSE CVE CVE-2020-11888 page
Описание
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
Затронутые продукты
openSUSE Leap 15.1:python2-markdown2-2.3.7-lp151.2.3.1
openSUSE Leap 15.1:python3-markdown2-2.3.7-lp151.2.3.1
Ссылки
- CVE-2020-11888
- SUSE Bug 1171379