Debian Security Advisory

DSA-4892-1 python-bleach -- security update

Date Reported:
18 Apr 2021
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 986251.
In Mitre's CVE dictionary: CVE-2021-23980.
More information:

It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when svg or math are in the allowed tags, 'p' or br are in allowed tags, style, title, noscript, script, textarea, noframes, iframe, or xmp are in allowed tags and 'strip_comments=False' is set.

For the stable distribution (buster), this problem has been fixed in version 3.1.2-0+deb10u2.

We recommend that you upgrade your python-bleach packages.

For the detailed security status of python-bleach please refer to its security tracker page at: