CVE-2021-23980

medium

Description

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

References

https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq

https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2021-23980

Details

Source: Mitre, NVD

Published: 2023-02-16

Updated: 2023-02-27

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium