UBUNTU-CVE-2018-7753
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-7753
UBUNTU-CVE-2018-7753
Summary:
Details: An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
References: https://ubuntu.com/security/CVE-2018-7753, https://github.com/mozilla/bleach/pull/356, https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef, https://bugs.debian.org/892252, https://github.com/mozilla/bleach/releases/tag/v2.1.3, https://www.cve.org/CVERecord?id=CVE-2018-7753, https://ubuntu.com/security/notices/USN-8077-1
Affected packages
Package
Name: python-bleach
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
