In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
References
Link | Resource |
---|---|
https://advisory.checkmarx.net/advisory/CX-2020-4277 | Exploit Third Party Advisory |
https://github.com/mozilla/bleach/security/advisories/GHSA-m6xf-fq7q-8743 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EDQU2SZLZMSSACCBUBJ6NOSRNNBDYFW5/ | |
https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mozilla
Published: 2020-03-24T21:15:40
Updated: 2021-03-30T22:35:40
Reserved: 2020-01-10T00:00:00
Link: CVE-2020-6816
JSON object: View
NVD Information
Status : Modified
Published: 2020-03-24T22:15:12.657
Modified: 2023-11-07T03:25:31.290
Link: CVE-2020-6816
JSON object: View
Redhat Information
No data.
CWE