CVE-2020-6816 describes a mutation Cross-Site Scripting (XSS) vulnerability in Mozilla Bleach versions prior to 3.12, affecting fedoraproject bleach and fedoraproject fedora. This medium-severity vulnerability (CVSS 6.1) can be triggered when bleach.clean is used with RCDATA and either SVG or Math tags whitelisted, and the 'strip' argument set to False, requiring user interaction for exploitation. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.2CPE matchmatch criteria | cpe:2.3:a:mozilla:bleach:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.