Debian Security Update DSA-4892 python-bleach - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
30
Reaction score
10
Credits
0
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when svg or math are in the allowed tags, 'p' or br are in allowed tags, style, title, noscript, script, textarea, noframes, iframe, or xmp are in allowed tags and 'strip_comments=False' is set.

Continue reading...
 


Top