Candidate: CVE-2017-15612 PublicDate: 2017-10-19 08:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15612 https://github.com/lepture/mistune/pull/140 Description: mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=879098 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_mistune: upstream_mistune: released (0.8-1) precise/esm_mistune: DNE trusty_mistune: DNE trusty/esm_mistune: DNE xenial_mistune: ignored (end of standard support, was needed) zesty_mistune: ignored (reached end-of-life) artful_mistune: ignored (reached end-of-life) bionic_mistune: not-affected (0.8.3-2) cosmic_mistune: not-affected (0.8.3-2) disco_mistune: not-affected (0.8.3-2) eoan_mistune: not-affected (0.8.3-2) focal_mistune: not-affected (0.8.3-2) groovy_mistune: not-affected (0.8.3-2) hirsute_mistune: not-affected (0.8.3-2) impish_mistune: not-affected (0.8.3-2) jammy_mistune: not-affected (0.8.3-2) devel_mistune: not-affected (0.8.3-2)