Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-6817
HistoryFeb 16, 2023 - 10:15 p.m.

Cross site scripting

2023-02-1622:15:00
PRIOn knowledge base
www.prio-n.com
4
cross site scripting
regular expression denial of service
bleach.clean vulnerability

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.7%

bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(…, attributes={‘a’: [‘style’]}).

CPENameOperatorVersion
bleachlt3.1.4

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.7%