Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqOXYtaDJ2cC0yaGh2

XSS in HtmlSanitizer

Impact

If you have explicitly allowed the <style> tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the <style> tag so there is no risk if you have not explicitly allowed the <style> tag.

Patches

The problem has been fixed in version 5.0.372.

Workarounds

Remove the <style> tag from the set of allowed tags.

For more information

If you have any questions or comments about this advisory open an issue in https://github.com/mganss/HtmlSanitizer

Credits

This issue was discovered by Michal Bentkowski of Securitum.

Permalink: https://github.com/advisories/GHSA-8j9v-h2vp-2hhv
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqOXYtaDJ2cC0yaGh2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 4 years ago
Updated: almost 2 years ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N

Identifiers: GHSA-8j9v-h2vp-2hhv, CVE-2020-26293
References: Repository: https://github.com/mganss/HtmlSanitizer
Blast Radius: 1.0

Affected Packages

nuget:HtmlSanitizer
Dependent packages: 116
Dependent repositories: 0
Downloads: 49,256,192 total
Affected Version Ranges: < 5.0.372
Fixed in: 5.0.372
All affected versions: 3.1.76, 3.1.79, 3.1.91, 3.1.93, 3.1.98, 3.2.103, 3.2.105, 3.3.142, 3.4.156, 4.0.179, 4.0.180, 4.0.181, 4.0.182, 4.0.183, 4.0.185, 4.0.187, 4.0.197, 4.0.199, 4.0.201, 4.0.204, 4.0.205, 4.0.207, 4.0.210, 4.0.217, 5.0.298, 5.0.304, 5.0.310, 5.0.319, 5.0.331, 5.0.342, 5.0.343, 5.0.353, 5.0.355
All unaffected versions: 5.0.372, 5.0.376, 5.0.404, 6.0.437, 6.0.441, 6.0.453, 7.0.473, 7.1.475, 7.1.488, 7.1.509, 7.1.512, 7.1.542, 8.0.601, 8.0.645, 8.0.692, 8.0.718, 8.0.723, 8.0.744, 8.0.746, 8.0.795, 8.0.811, 8.0.838, 8.0.843, 8.0.865, 8.1.870