It was discovered that Bleach did not properly sanitize URI attributes containing character entities. An attacker could possibly use this issue to construct a URI with a disallowed scheme that would bypass sanitization, leading to cross-site scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-7753)
Yaniv Nizry discovered that Bleach was vulnerable to a mutation cross-site scripting issue when sanitizing HTML with the noscript tag and a raw tag in the allowed tags list. An attacker could possibly use this issue to inject malicious content, leading to cross-site scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-6802)
Yaniv Nizry discovered that Bleach was vulnerable to a mutation cross-site scripting issue when sanitizing HTML with RCDATA together with svg or math tags in the allowed tags list. An attacker could possibly use this issue to inject malicious content, leading to cross-site scripting. (CVE-2020-6816)
It was discovered that Bleach incorrectly handled parsing of style attributes when sanitizing HTML. An attacker could possibly use this issue to perform a regular expression denial of service, leading to excessive resource consumption. (CVE-2020-6817)
Yaniv Nizry and Michał Bentkowski discovered that Bleach was vulnerable to a mutation cross-site scripting issue when sanitizing HTML with certain combinations of allowed tags. An attacker could possibly use this issue to inject malicious content, leading to cross-site scripting. (CVE-2021-23980)
{
"binaries": [
{
"binary_version": "1.4.2-1ubuntu0.1~esm1",
"binary_name": "python-bleach"
},
{
"binary_version": "1.4.2-1ubuntu0.1~esm1",
"binary_name": "python3-bleach"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:16.04:LTS",
"cves": [
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6816"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6817"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2021-23980"
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8077-1.json"
{
"binaries": [
{
"binary_version": "2.1.2-1ubuntu0.1~esm1",
"binary_name": "python-bleach"
},
{
"binary_version": "2.1.2-1ubuntu0.1~esm1",
"binary_name": "python3-bleach"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:18.04:LTS",
"cves": [
{
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2018-7753"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6802"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6816"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6817"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2021-23980"
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8077-1.json"
{
"binaries": [
{
"binary_version": "3.1.1-1ubuntu0.1~esm1",
"binary_name": "python3-bleach"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:20.04:LTS",
"cves": [
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6816"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2020-6817"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2021-23980"
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8077-1.json"