Candidate: CVE-2020-6816 PublicDate: 2020-03-24 22:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6816 https://bugzilla.mozilla.org/show_bug.cgi?id=1621692 (not public) https://github.com/mozilla/bleach/security/advisories/GHSA-m6xf-fq7q-8743 https://github.com/mozilla/bleach/commit/175f67740e7951e1d80cefb7831e6c3e4efeb986 Description: In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=954236 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_python-bleach: upstream_python-bleach: released (3.1.3-1) precise/esm_python-bleach: DNE trusty_python-bleach: ignored (out of standard support) trusty/esm_python-bleach: DNE xenial_python-bleach: ignored (end of standard support, was needed) bionic_python-bleach: needed eoan_python-bleach: ignored (reached end-of-life) focal_python-bleach: needed groovy_python-bleach: not-affected (3.2.1-1) hirsute_python-bleach: not-affected (3.2.1-2) impish_python-bleach: not-affected (3.2.1-2) jammy_python-bleach: not-affected (3.2.1-2) devel_python-bleach: not-affected (3.2.1-2)