9.8
CVSSv3

CVE-2018-7753

Published: 07/03/2018 Updated: 29/03/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Bleach 2.1.x prior to 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bleach 2.1

mozilla bleach 2.1.2

mozilla bleach 2.1.1

Vendor Advisories

Debian Bug report logs - #892252 python-bleach: CVE-2018-7753: URI values with character entities not properly sanitized Package: src:python-bleach; Maintainer for src:python-bleach is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Scott Kitterman <debian@kittermancom> Date: We ...