ELA-411-1 python-bleach security update

mutation XSS

2021-04-26
Packagepython-bleach
Version1.4-1+deb8u2
Related CVEs CVE-2021-23980


It was discovered that python-bleach, a whitelist-based HTML-sanitizing library for the Python language, is prone to a mutation XSS vulnerability in bleach.clean when ‘svg’ or ‘math’ are in the allowed tags, ‘p’ or ‘br’ are in allowed tags, ‘style’, ’title’, ’noscript’, ‘script’, ’textarea’, ’noframes’, ‘iframe’, or ‘xmp’ are in allowed tags and ‘strip_comments=False’ is set.



For Debian 8 jessie, these problems have been fixed in version 1.4-1+deb8u2.

We recommend that you upgrade your python-bleach packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.