An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-0026 An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Github GHSA Github GHSA GHSA-m9mq-p2f9-cfqv Bleach URI Scheme Restriction Bypass
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T01:25:52.866Z

Reserved: 2018-03-07T00:00:00Z

Link: CVE-2018-7753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-07T23:29:00.273

Modified: 2024-11-21T04:12:40.100

Link: CVE-2018-7753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.