In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mozilla/bleach/security/advisories/GHSA-m6xf-fq7q-8743 | third party advisory |
https://www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach | third party advisory exploit |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EDQU2SZLZMSSACCBUBJ6NOSRNNBDYFW5/ | vendor advisory |
https://advisory.checkmarx.net/advisory/CX-2020-4277 | third party advisory exploit |