CVE-2021-23980
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note:…
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mozilla/bleach
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2021-23980Exploit, Issue Tracking
- https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpqVendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2021-23980Exploit, Issue Tracking
- https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpqVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.