Hide Forgot
When pasting a `<style>` tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2020-02/#CVE-2019-17022
Acknowledgments: Name: the Mozilla project Upstream: Michał Bentkowski
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:0086 https://access.redhat.com/errata/RHSA-2020:0086
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:0085 https://access.redhat.com/errata/RHSA-2020:0085
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-17022
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:0111 https://access.redhat.com/errata/RHSA-2020:0111
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:0123 https://access.redhat.com/errata/RHSA-2020:0123
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:0120 https://access.redhat.com/errata/RHSA-2020:0120
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:0127 https://access.redhat.com/errata/RHSA-2020:0127
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:0292 https://access.redhat.com/errata/RHSA-2020:0292
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:0295 https://access.redhat.com/errata/RHSA-2020:0295