In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
[
{
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"deprecated": false,
"digest": {
"length": 1498.0,
"function_hash": "327506727195512130857608281471890945436"
},
"signature_type": "Function",
"id": "CVE-2020-4070-27bf7adc",
"target": {
"function": "parseURL",
"file": "org/w3c/css/css/StyleSheetParser.java"
}
},
{
"signature_version": "v1",
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"deprecated": false,
"digest": {
"line_hashes": [
"287126531491259831142828594517899965709",
"166151882237851564633381564464035597352",
"217623342706874349683039718344875380745",
"25486391784260251365600363288280579394"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2020-4070-dd4b0a2a",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-4070.json"