Candidate: CVE-2017-16876 PublicDate: 2017-12-29 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16876 https://github.com/lepture/mistune/commit/5f06d724bc05580e7f203db2d4a4905fc1127f98 Description: Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_mistune: upstream_mistune: released (0.8.1-1) precise/esm_mistune: DNE trusty_mistune: DNE trusty/esm_mistune: DNE xenial_mistune: ignored (end of standard support, was needed) zesty_mistune: ignored (reached end-of-life) artful_mistune: ignored (reached end-of-life) bionic_mistune: not-affected (0.8.1-1) cosmic_mistune: not-affected (0.8.1-1) disco_mistune: not-affected (0.8.1-1) eoan_mistune: not-affected (0.8.1-1) focal_mistune: not-affected (0.8.1-1) groovy_mistune: not-affected (0.8.1-1) hirsute_mistune: not-affected (0.8.1-1) impish_mistune: not-affected (0.8.1-1) jammy_mistune: not-affected (0.8.1-1) devel_mistune: not-affected (0.8.1-1)