python-bleach

Edit Package python-bleach
No description set
Refresh
Refresh
Source Files
Filename Size Changed
bleach-3.1.4.tar.gz 0000177813 174 KB
de-vendor.patch 0000001775 1.73 KB
python-bleach.changes 0000011317 11.1 KB
python-bleach.spec 0000002587 2.53 KB
Revision 10 (latest revision is 20)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 790549 from Dirk Mueller's avatar Dirk Mueller (dirkmueller) (revision 10)
- update to 3.1.4 (bsc#1168280, CVE-2020-6817):
  * ``bleach.clean`` behavior parsing style attributes could result in a
    regular expression denial of service (ReDoS).
    Calls to ``bleach.clean`` with an allowed tag with an allowed
    ``style`` attribute were vulnerable to ReDoS. For example,
    ``bleach.clean(..., attributes={'a': ['style']})``.
  * Style attributes with dashes, or single or double quoted values are
    cleaned instead of passed through.

- update to 3.1.3 (bsc#1167379, CVE-2020-6816):
Comments 0
openSUSE Build Service is sponsored by