Vulnerability Description
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Bleach | 2.1 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/892252Third Party Advisory
- https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ePatchThird Party Advisory
- https://github.com/mozilla/bleach/releases/tag/v2.1.3Third Party Advisory
- https://bugs.debian.org/892252Third Party Advisory
- https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ePatchThird Party Advisory
- https://github.com/mozilla/bleach/releases/tag/v2.1.3Third Party Advisory
FAQ
What is CVE-2018-7753?
CVE-2018-7753 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible t...
How severe is CVE-2018-7753?
CVE-2018-7753 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-7753?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Bleach.