The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bluemonday | Microco | * | 1.0.16 (excluding) |
Golang-github-microcosm-cc-bluemonday | Ubuntu | bionic | * |
Golang-github-microcosm-cc-bluemonday | Ubuntu | hirsute | * |
Golang-github-microcosm-cc-bluemonday | Ubuntu | impish | * |
Golang-github-microcosm-cc-bluemonday | Ubuntu | trusty | * |
Golang-github-microcosm-cc-bluemonday | Ubuntu | upstream | * |
Golang-github-microcosm-cc-bluemonday | Ubuntu | xenial | * |