Executive brief
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
Affected products
- PyPI bleach
Junglewise Threat Intelligence
CVE-2020-6816 · Severity: low · CVSS 3.1 · Published 2020-03-24
Technologies: bleach (PyPI). Vendors: PyPI.
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.