CVE-2020-6802
Summary
| CVE | CVE-2020-6802 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-24 22:15:00 UTC |
| Updated | 2023-11-07 03:25:00 UTC |
| Description | In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: python-bleach-3.1.4-2.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: python-bleach-3.1.4-2.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| mutation XSS in bleach.clean when noscript and raw tag whitelisted · Advisory · mozilla/bleach · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: python-bleach-3.1.4-2.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 31 Update: python-bleach-3.1.4-2.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 30 Update: python-bleach-3.1.4-2.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: python-bleach-3.1.4-2.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Mutation Cross-Site Scripting (mXSS) Vulnerabilities Discovered in Mozilla-Bleach |
MISC |
www.checkmarx.com |
Exploit, Third Party Advisory |
| advisory.checkmarx.net/advisory/CX-2020-4276 |
MISC |
advisory.checkmarx.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501361 Alpine Linux Security Update for py3-bleach
- 981587 Python (pip) Security Update for bleach (GHSA-q65m-pv3f-wr5r)