Junglewise Threat Intelligence

CVE-2020-6816: PYSEC-2020-28 - In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argume

CVE-2020-6816 · Severity: low · CVSS 3.1 · Published 2020-03-24

Technologies: bleach (PyPI). Vendors: PyPI.

Executive brief

In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.

Affected products

  • PyPI bleach

Related threats