[DOMPurify Security] New Release Version 2.0.3 (Security Issue)

Security Announcements for DOMPurify and related tools dompurify-security at lists.ruhr-uni-bochum.de
Wed Sep 25 18:33:05 CEST 2019


*Intro*

A new version of DOMPurify was released today: DOMPurify 2.0.3

*Background*

Following the release of DOMPurify 2.0.2, another mXSS variation,
spotted by Michał Bentkowski was addressed and fixed. This time, the
attack made use of a special property exposed by template elements.

*Fix*

DOMPurify is now more aware of this and comparable browser issues
and changes the sanitization behavior to be more secure. The fix has
been reviewed by the original finder as well.

*Packages*

Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/2.0.3

EOF

-- 
Fon  +49 1520 8675 782
PGP  0xC26C858090F70ADA

cure53.de || keybase.io/cure53 || @cure53berlin

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.ruhr-uni-bochum.de/pipermail/dompurify-security/attachments/20190925/28711da9/attachment.sig>


More information about the DOMPurify-Security mailing list