A mutation XSS affects users calling bleach.clean
with all of:
svg
or math
in the allowed/whitelisted tagsstrip=False
Users are encouraged to upgrade to bleach v3.1.2 or greater.
bleach.clean
calls to use strip=True
, or not whitelist math
or svg
tags and one or more of the following tags:script
noscript
style
noframes
xmp
noembed
iframe
unsafe-inline
and unsafe-eval
script-src
s) will also help mitigate the risk.If you have any questions or comments about this advisory:
advisory.checkmarx.net/advisory/CX-2020-4277
github.com/mozilla/bleach/releases/tag/v3.1.2
github.com/mozilla/bleach/security/advisories/GHSA-m6xf-fq7q-8743
lists.fedoraproject.org/archives/list/[email protected]/message/EDQU2SZLZMSSACCBUBJ6NOSRNNBDYFW5
nvd.nist.gov/vuln/detail/CVE-2020-6816
www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleach