Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-7753

Опубликовано: 07 мар. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

3.2.1-2
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

3.1.1-1
esm-apps/jammy

not-affected

3.2.1-2
esm-apps/noble

not-affected

3.2.1-2

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

CVSS3: 9.8
debian
почти 8 лет назад

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that ...

CVSS3: 9.8
github
около 7 лет назад

Bleach URI Scheme Restriction Bypass

7.5 High

CVSS2

9.8 Critical

CVSS3