QID 980991
QID 980991: Python (pip) Security Update for bleach (GHSA-m9mq-p2f9-cfqv)
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m9mq-p2f9-cfqv for updates pertaining to this vulnerability.
Vendor References
- GHSA-m9mq-p2f9-cfqv -
github.com/advisories/GHSA-m9mq-p2f9-cfqv
CVEs related to QID 980991
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m9mq-p2f9-cfqv | bleach |
|