Lucene search

K
osvGoogleOSV:CVE-2019-10772
HistoryDec 11, 2019 - 4:15 p.m.

CVE-2019-10772

2019-12-1116:15:10
Google
osv.dev
2

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.3%

It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the “xlink:href” attribute due to mishandling of the xlink namespace by the sanitizer.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for OSV:CVE-2019-10772