Cross-Site Scripting Vulnerability in Bleach by Mozilla
CVE-2021-23980
What is CVE-2021-23980?
A cross-site scripting vulnerability in Bleach allows attackers to manipulate user inputs by using mutation XSS. This occurs when users invoke bleach.clean with specific conditions, permitting SVG or math content within certain allowed HTML tags (p or br) while restricting others. Notably, the tags style, title, noscript, script, textarea, noframes, iframe, or xmp are permissible, particularly with the keyword argument strip_comments set to False. Due to defaults like strip_comments being True, certain contexts may expose users to potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mozilla Bleach < 3.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved