Bugzilla – Bug 1168280
VUL-0: CVE-2020-6817: python-bleach: Regular expression denial of service in BleachSanitizerFilter.sanitize_css
Last modified: 2021-04-18 01:16:13 UTC
CVE-2020-6817 bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}). Workarounds: do not whitelist the style attribute in bleach.clean calls limit input string length References https://bugzilla.mozilla.org/show_bug.cgi?id=1623633 https://www.regular-expressions.info/redos.html https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6817 https://github.com/mozilla/bleach/security/advisories/GHSA-vqhp-cxgc-6wmm
submitted to factory. when accepted there I'll submit it from factory to leap (to reset the origin). hopefully it won't get rejected this time around.
This is an autogenerated message for OBS integration: This bug (1168280) was mentioned in https://build.opensuse.org/request/show/790549 Factory / python-bleach
This is an autogenerated message for OBS integration: This bug (1168280) was mentioned in https://build.opensuse.org/request/show/884912 15.2 / python-bleach
openSUSE-SU-2021:0552-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1167379,1168280,1184547 CVE References: CVE-2020-6816,CVE-2020-6817,CVE-2021-23980 JIRA References: Sources used: openSUSE Leap 15.2 (src): python-bleach-3.1.5-lp152.2.3.1
for Leap 15.3: openSUSE:Backports:SLE-15-SP3/python-bleach https://build.opensuse.org/request/show/885464 otherwise done.
openSUSE-SU-2021:0571-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1167379,1168280,1184547 CVE References: CVE-2020-6816,CVE-2020-6817,CVE-2021-23980 JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): python-bleach-3.1.5-bp152.2.4.1