GHSA-m9mq-p2f9-cfqv
Dashboard / Vulnerabilities / GHSA-m9mq-p2f9-cfqv
GHSA-m9mq-p2f9-cfqv
Summary: Bleach URI Scheme Restriction Bypass
Details: An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-7753, https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef, https://bugs.debian.org/892252, https://github.com/mozilla/bleach, https://github.com/mozilla/bleach/releases/tag/v2.1.3, https://github.com/pypa/advisory-database/tree/main/vulns/bleach/PYSEC-2018-51.yaml
Affected packages
Package
Name: bleach
Purl: pkg:pypi/bleach
Affected ranges
Type: ECOSYSTEM
Events:
