[DOMPurify Security] New Release Version 2.0.16 (Security Issue)
Security Announcements for DOMPurify and related tools
dompurify-security at lists.ruhr-uni-bochum.de
Fri Sep 18 14:36:52 CEST 2020
*Intro*
A new version of DOMPurify was released today: DOMPurify 2.0.16
*Background*
An mXSS-based bypass was spotted by Michał Bentkowski. The issue was
addressed and fixed in this release, the fix was reviewed by the finder.
*Fix*
DOMPurify is now aware of the behavior caused by nested forms inside and
around MathML elements and aggressively scrubs those for better security.
*Packages*
Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/2.0.16
EOF
--
Fon +49 1520 8675 782
PGP 0xC26C858090F70ADA
cure53.de || keybase.io/cure53 || @cure53berlin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.ruhr-uni-bochum.de/pipermail/dompurify-security/attachments/20200918/665036ee/attachment.sig>
More information about the DOMPurify-Security
mailing list