Medium severity6.1OSV Advisory· Published Mar 24, 2020· Updated Jun 17, 2026
CVE-2020-6802
CVE-2020-6802
Description
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bleachPyPI | < 3.1.1 | 3.1.1 |
Affected products
100.1.2, 0.2.0, 0.2.1, …+ 1 more
- (no CPE)range: 0.1.2, 0.2.0, 0.2.1, …
- cpe:2.3:a:mozilla:bleach:*:*:*:*:*:*:*:*range: <3.1.1
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- ghsa-coords5 versionspkg:pypi/bleachpkg:rpm/opensuse/python-bleach&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python-bleach&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/weblate&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-bleach&distro=SUSE%20Package%20Hub%2015%20SP1
< 3.1.1+ 4 more
- (no CPE)range: < 3.1.1
- (no CPE)range: < 3.1.1-lp151.3.6.1
- (no CPE)range: < 6.1.0-1.5
- (no CPE)range: < 4.8.1-1.1
- (no CPE)range: < 3.1.1-bp151.4.4.1
Patches
Vulnerability mechanics
References
15- advisory.checkmarx.net/advisory/CX-2020-4276nvdExploitThird Party AdvisoryWEB
- www.checkmarx.com/blog/vulnerabilities-discovered-in-mozilla-bleachnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-q65m-pv3f-wr5rghsaADVISORY
- github.com/mozilla/bleach/security/advisories/GHSA-q65m-pv3f-wr5rnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-6802ghsaADVISORY
- bugzilla.mozilla.org/show_bug.cgighsaWEB
- cure53.de/fp170.pdfghsaWEB
- github.com/mozilla/bleach/commit/f77e0f6392177a06e46a49abd61a4d9f035e57fdghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/bleach/PYSEC-2020-27.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/72R4VFFHDRSQMNT7IZU3X2755ZP4HGNIghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/OCNLM2MGQTOLCIVVYS2Z5S7KOQJR5JC4ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/YTULPQB7HVPPYWEYVNHJGDTSPVIDHIZXghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/72R4VFFHDRSQMNT7IZU3X2755ZP4HGNI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OCNLM2MGQTOLCIVVYS2Z5S7KOQJR5JC4/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YTULPQB7HVPPYWEYVNHJGDTSPVIDHIZX/nvd
News mentions
0No linked articles in our index yet.