VDB

GCVE-VVD-MAGEIA-2021-260

GCVE-VVD-MAGEIA-2021-260
Advisory Published
Vulnetix · Advisory published June 16, 2021
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980).

Affected Products

VendorProductVersionsPlatforms
Mageiapython-bleach0 (affected), 3.1.4-1.1.mga7 (unaffected)
Mageiapython-bleach0 (affected), 3.3.0-1.mga8 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›