GO-2022-0588
Dashboard / Vulnerabilities / GO-2022-0588
GO-2022-0588
Summary: Cross-site scripting via leaked style elements in github.com/microcosm-cc/bluemonday
Details: The bluemonday HTML sanitizer can leak the contents of a "style" element into HTML output, potentially causing XSS vulnerabilities. The default bluemonday sanitization policies are not vulnerable. Only user-defined policies allowing "select", "style", and "option" elements are affected. Permitting the "style" element in policies is hazardous, because bluemonday does not contain a CSS sanitizer. Newer versions of bluemonday suppress "style" and "script" elements even when allowed by a policy unless the policy explicitly requests unsafe processing.
References: https://github.com/microcosm-cc/bluemonday/commit/c788a2a4d42e081ad54a31368478820bb4a42fb4, https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/
Affected packages
Package
Name: github.com/microcosm-cc/bluemonday
Purl: pkg:golang/github.com/microcosm-cc/bluemonday
Affected ranges
Type: SEMVER
Events:
