Candidate: CVE-2020-11888 PublicDate: 2020-04-20 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11888 https://github.com/trentm/python-markdown2/issues/348 Description: python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_python-markdown2: upstream_python-markdown2: needs-triage precise/esm_python-markdown2: DNE trusty_python-markdown2: ignored (out of standard support) trusty/esm_python-markdown2: DNE xenial_python-markdown2: DNE bionic_python-markdown2: DNE eoan_python-markdown2: ignored (reached end-of-life) focal_python-markdown2: needs-triage groovy_python-markdown2: not-affected (2.3.9-1) hirsute_python-markdown2: not-affected (2.3.9-1) impish_python-markdown2: not-affected (2.3.9-1) jammy_python-markdown2: not-affected (2.3.9-1) devel_python-markdown2: not-affected (2.3.9-1)