It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when 'svg' or 'math' are in the allowed tags, 'p' or 'br' are in allowed tags, 'style', 'title', 'noscript', 'script', 'textarea', 'noframes', . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4892-1
The updated packages fix a security vulnerability: Mutation XSS in bleach.clean when noscript and raw tag whitelisted. (CVE-2020-6802) . MGASA-2020-0125 - Updated python-bleach packages fix security vulnerability Publication date: 06 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0125.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-6802 The updated packages fix a security vulnerability: Mutation XSS in bleach.clean when noscript and raw tag whitelisted. (CVE-2020-6802) References: - https://bugs.mageia.org/show_bug.cgi?id=26286 - https://lists.debian.org/debian-security-announce/2020/msg00039.html - https://www.cve.org/CVERecord?id=CVE-2020-6802 SRPMS: - 7/core/python-bleach-3.1.1-1.mga7 . Mageia security fix for python-bleach addresses an XSS vulnerability in clean function. Critical solution for users.. Mageia Security, python-bleach, XSS Fix. . LinuxSecurity.com Team
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when 'noscript' and one or more raw text tags were whitelisted. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4636-1
Get the latest Linux and open source security news straight to your inbox.