Security Advisory

CVE-2018-7753

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-07 23:00:00
Last updated 2024-09-17 01:25:52
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.