[DOMPurify Security] New Release Version 0.7.4 (Security Issue)

Security Announcements for DOMPurify and related tools dompurify-security at lists.ruhr-uni-bochum.de
Wed Feb 17 15:08:21 CET 2016


*Intro*

A new version of DOMPurify was released today: DOMPurify 0.7.4

*Background*

One potential security issue was spotted, exclusively affecting the
(default-off) SAFE_FOR_TEMPLATING mode, where malformed HTML could cause
passive XSS. This problem has been reported by @filedescriptor.

*Example*

Details about the problem can be found here:
https://github.com/cure53/DOMPurify/blob/master/test/test-suite.js#L81

*Fix*

The fix commit is available here:
https://github.com/cure53/DOMPurify/commit/ad16112f64beb8e7a41b3f023261c15f24b9ea53

*Packages*

Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/0.7.4

EOF

-- 
Fon    +49 1520 8675782
PGP    0xD33441A8
S/MIME kuix.de/smime-keyserver/

cure53.de || mario.heideri.ch || 0x6D6172696F

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: OpenPGP digital signature
URL: <http://lists.ruhr-uni-bochum.de/pipermail/dompurify-security/attachments/20160217/55437ea9/attachment.sig>


More information about the DOMPurify-Security mailing list