Open dev-mend-for-github-com[bot] opened 2 years ago
:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.
:information_source: This issue was automatically re-opened by WhiteSource because the vulnerable library in the specific branch(es) has been detected in the WhiteSource inventory.
Vulnerable Library - bleach-1.0.1.tar.gz
An easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Vulnerabilities
Details
CVE-2020-6817
### Vulnerable Library - bleach-1.0.1.tar.gzAn easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Dependency Hierarchy: - :x: **bleach-1.0.1.tar.gz** (Vulnerable Library)
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Found in base branch: main
### Vulnerability DetailsA regular expression denial-of-service (ReDoS) found in Bleach before 3.1.4.
Publish Date: 2020-04-01
URL: CVE-2020-6817
### CVSS 3 Score Details (7.5)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/mozilla/bleach/releases/tag/v3.1.4
Release Date: 2020-04-01
Fix Resolution: bleach - 3.1.4
CVE-2020-6816
### Vulnerable Library - bleach-1.0.1.tar.gzAn easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Dependency Hierarchy: - :x: **bleach-1.0.1.tar.gz** (Vulnerable Library)
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Found in base branch: main
### Vulnerability DetailsIn Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
Publish Date: 2020-03-24
URL: CVE-2020-6816
### CVSS 3 Score Details (6.1)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/mozilla/bleach/security/advisories/GHSA-m6xf-fq7q-8743
Release Date: 2020-03-24
Fix Resolution: bleach - 3.1.2
CVE-2020-6802
### Vulnerable Library - bleach-1.0.1.tar.gzAn easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Dependency Hierarchy: - :x: **bleach-1.0.1.tar.gz** (Vulnerable Library)
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Found in base branch: main
### Vulnerability DetailsIn Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
Publish Date: 2020-03-24
URL: CVE-2020-6802
### CVSS 3 Score Details (6.1)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/advisories/GHSA-q65m-pv3f-wr5r
Release Date: 2020-03-24
Fix Resolution: 3.1.1
WS-2021-0011
### Vulnerable Library - bleach-1.0.1.tar.gzAn easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Dependency Hierarchy: - :x: **bleach-1.0.1.tar.gz** (Vulnerable Library)
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Found in base branch: main
### Vulnerability DetailsIn Mozilla Bleach before 3.3.0, a mutation XSS in bleach.clean when p, br, style, title, noscript, script, textarea, noframes, iframe, or xmp and either svg or math tags are whitelisted and the keyword argument strip_comments=False.
Publish Date: 2021-02-01
URL: WS-2021-0011
### CVSS 3 Score Details (6.1)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/advisories/GHSA-vv2x-vrpj-qqpq
Release Date: 2021-02-01
Fix Resolution: bleach - 3.3.0
CVE-2021-23980
### Vulnerable Library - bleach-1.0.1.tar.gzAn easy safelist-based HTML-sanitizing tool.
Library home page: https://files.pythonhosted.org/packages/25/f5/6a3aa89014d70e1d76172917d7bf06443c8ab2c3c528859d8f15e8e6b1cf/bleach-1.0.1.tar.gz
Dependency Hierarchy: - :x: **bleach-1.0.1.tar.gz** (Vulnerable Library)
Found in HEAD commit: eed028302ce87562f8171a72aca1fa6f0f49e59d
Found in base branch: main
### Vulnerability DetailsA flaw was found in bleach before 3.3.0. A mutation XSS affects users calling "bleach.clean". This was fixed in commit 1334134
Publish Date: 2021-01-14
URL: CVE-2021-23980
### CVSS 3 Score Details (6.1)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Changed - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq
Release Date: 2021-01-14
Fix Resolution: v3.3.0