UBUNTU-CVE-2024-34078

Source
https://ubuntu.com/security/CVE-2024-34078
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-34078.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-34078
Related
Published
2024-05-06T15:15:00Z
Modified
2025-01-13T10:25:16Z
Summary
[none]
Details

html-sanitizer is an allowlist-based HTML cleaner. If using keep_typographic_whitespace=False (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons; this allows specially crafted HTML to escape sanitization. The problem has been fixed in 2.4.2.

References

Affected packages

Ubuntu:22.04:LTS / python-html-sanitizer

Package

Name
python-html-sanitizer
Purl
pkg:deb/ubuntu/python-html-sanitizer@1.9.3-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.1-2
1.9.3-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / python-html-sanitizer

Package

Name
python-html-sanitizer
Purl
pkg:deb/ubuntu/python-html-sanitizer@2.2-1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / python-html-sanitizer

Package

Name
python-html-sanitizer
Purl
pkg:deb/ubuntu/python-html-sanitizer@2.2-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.2-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}