Candidate: CVE-2020-6802 PublicDate: 2020-03-24 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6802 https://bugzilla.mozilla.org/show_bug.cgi?id=1615315 (not public) https://github.com/mozilla/bleach/security/advisories/GHSA-q65m-pv3f-wr5r https://github.com/mozilla/bleach/commit/f77e0f6392177a06e46a49abd61a4d9f035e57fd Description: In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=951907 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_python-bleach: upstream_python-bleach: released (3.1.1-1) precise/esm_python-bleach: DNE trusty_python-bleach: ignored (out of standard support) trusty/esm_python-bleach: DNE xenial_python-bleach: ignored (end of standard support, was needed) bionic_python-bleach: needed eoan_python-bleach: ignored (reached end-of-life) focal_python-bleach: not-affected (3.1.1-1) groovy_python-bleach: not-affected (3.1.1-1) hirsute_python-bleach: not-affected (3.1.1-1) impish_python-bleach: not-affected (3.1.1-1) jammy_python-bleach: not-affected (3.1.1-1) devel_python-bleach: not-affected (3.1.1-1)