CVE Vulnerabilities

CVE-2021-42576

Published: Oct 18, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Affected Software

NameVendorStart VersionEnd Version
BluemondayMicroco*1.0.16 (excluding)
Golang-github-microcosm-cc-bluemondayUbuntubionic*
Golang-github-microcosm-cc-bluemondayUbuntuhirsute*
Golang-github-microcosm-cc-bluemondayUbuntuimpish*
Golang-github-microcosm-cc-bluemondayUbuntutrusty*
Golang-github-microcosm-cc-bluemondayUbuntuupstream*
Golang-github-microcosm-cc-bluemondayUbuntuxenial*

References