Lucene search

K
osvGoogleOSV:PYSEC-2018-51
HistoryMar 07, 2018 - 11:29 p.m.

PYSEC-2018-51

2018-03-0723:29:00
Google
osv.dev
16

EPSS

0.003

Percentile

70.6%

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values werenโ€™t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.