Bug 2027197 (CVE-2021-42576) - CVE-2021-42576 bluemonday: improper policies enforcement may lead to remote code execution
Summary: CVE-2021-42576 bluemonday: improper policies enforcement may lead to remote c...
Keywords:
Status: NEW
Alias: CVE-2021-42576
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2027199
TreeView+ depends on / blocked
 
Reported: 2021-11-29 05:57 UTC by Marian Rehak
Modified: 2023-07-07 08:35 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2021-11-29 05:57:56 UTC
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

External Reference:

https://docs.google.com/document/d/11SoX296sMS0XoQiQbpxc5pNxSdbJKDJkm5BDv0zrX50/

Comment 1 lnacshon 2021-11-29 10:27:24 UTC
Seems that all our services are using bluemonday in go prior to 1.0.16


Note You need to log in before you can comment on or make changes to this bug.