Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqOXYtaDJ2cC0yaGh2
XSS in HtmlSanitizer
Impact
If you have explicitly allowed the <style>
tag, an attacker could craft HTML that includes script after passing through the sanitizer. The default settings disallow the <style>
tag so there is no risk if you have not explicitly allowed the <style>
tag.
Patches
The problem has been fixed in version 5.0.372.
Workarounds
Remove the <style>
tag from the set of allowed tags.
For more information
If you have any questions or comments about this advisory open an issue in https://github.com/mganss/HtmlSanitizer
Credits
This issue was discovered by Michal Bentkowski of Securitum.
Permalink: https://github.com/advisories/GHSA-8j9v-h2vp-2hhvJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThqOXYtaDJ2cC0yaGh2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 4 years ago
Updated: almost 2 years ago
CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N
Identifiers: GHSA-8j9v-h2vp-2hhv, CVE-2020-26293
References:
- https://github.com/mganss/HtmlSanitizer/security/advisories/GHSA-8j9v-h2vp-2hhv
- https://github.com/mganss/HtmlSanitizer/releases/tag/v5.0.372
- https://www.nuget.org/packages/HtmlSanitizer/
- https://nvd.nist.gov/vuln/detail/CVE-2020-26293
- https://github.com/mganss/HtmlSanitizer/commit/a3a7602a44d4155d51ec0fbbedc2a49e9c7e2eb8
- https://github.com/advisories/GHSA-8j9v-h2vp-2hhv
Blast Radius: 1.0
Affected Packages
nuget:HtmlSanitizer
Dependent packages: 116Dependent repositories: 0
Downloads: 49,256,192 total
Affected Version Ranges: < 5.0.372
Fixed in: 5.0.372
All affected versions: 3.1.76, 3.1.79, 3.1.91, 3.1.93, 3.1.98, 3.2.103, 3.2.105, 3.3.142, 3.4.156, 4.0.179, 4.0.180, 4.0.181, 4.0.182, 4.0.183, 4.0.185, 4.0.187, 4.0.197, 4.0.199, 4.0.201, 4.0.204, 4.0.205, 4.0.207, 4.0.210, 4.0.217, 5.0.298, 5.0.304, 5.0.310, 5.0.319, 5.0.331, 5.0.342, 5.0.343, 5.0.353, 5.0.355
All unaffected versions: 5.0.372, 5.0.376, 5.0.404, 6.0.437, 6.0.441, 6.0.453, 7.0.473, 7.1.475, 7.1.488, 7.1.509, 7.1.512, 7.1.542, 8.0.601, 8.0.645, 8.0.692, 8.0.718, 8.0.723, 8.0.744, 8.0.746, 8.0.795, 8.0.811, 8.0.838, 8.0.843, 8.0.865, 8.1.870