All errata/sisyphus/ALT-PU-2018-3701-1
ALT-PU-2018-3701-1

Package update python-module-bleach in branch sisyphus

Version2.1.3-alt1
Published2018-06-09
Max severityCRITICAL
Severity:

Closed issues (2)

CVE-2018-7753
CRITICAL9.8

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Published: 2018-03-07Modified: 2024-11-21
CVSS 2.0HIGH 7.5
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS 3.xCRITICAL 9.8
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GHSA-m9mq-p2f9-cfqv
CRITICAL9.3

Bleach URI Scheme Restriction Bypass

Published: 2019-01-04Modified: 2024-09-04
CVSS 3.xCRITICAL 9.3
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 4.0CRITICAL 9.3
CVSS:4.0/CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N