CVE Vulnerabilities

CVE-2021-42576

Published: Oct 18, 2021 | Modified: Aug 08, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.

Affected Software

Name Vendor Start Version End Version
Bluemonday Microco * 1.0.16 (excluding)
Golang-github-microcosm-cc-bluemonday Ubuntu bionic *
Golang-github-microcosm-cc-bluemonday Ubuntu hirsute *
Golang-github-microcosm-cc-bluemonday Ubuntu impish *
Golang-github-microcosm-cc-bluemonday Ubuntu trusty *
Golang-github-microcosm-cc-bluemonday Ubuntu upstream *
Golang-github-microcosm-cc-bluemonday Ubuntu xenial *

References