Debian 10225 Published by

A python-bleach security update has been released for Debian GNU/Linux 8 Extended LTS to address a XSS vulnerability.



ELA-411-1 python-bleach security update

Package python-bleach
Version 1.4-1+deb8u2
Related CVEs CVE-2021-23980

It was discovered that python-bleach, a whitelist-based HTML-sanitizing library for the Python language, is prone to a mutation XSS vulnerability in bleach.clean when ‘svg’ or ‘math’ are in the allowed tags, ‘p’ or ‘br’ are in allowed tags, ‘style’, ‘title’, ‘noscript’, ‘script’, ‘textarea’, ‘noframes’, ‘iframe’, or ‘xmp’ are in allowed tags and ‘strip_comments=False’ is set.

For Debian 8 jessie, these problems have been fixed in version 1.4-1+deb8u2.

We recommend that you upgrade your python-bleach packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-411-1 python-bleach security update