VDB

PYSEC-2018-51

PYSEC-2018-51 PUBLISHED

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Affected Products

VendorProductVersions
PyPIbleach0, 2.1, 2.1.2

Timeline

  • Mar 7, 2018 CVE Published
  • Nov 8, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›