Bypassing Cross-Site Scripting Protection in TYPO3 HTML Sanitizer
Moderate severity
GitHub Reviewed
Published
Nov 14, 2023
in
TYPO3/html-sanitizer
•
Updated Nov 15, 2023
Package
Affected versions
>= 1.0.0, <= 1.5.2
>= 2.0.0, <= 2.1.3
Patched versions
1.5.3
2.1.4
Description
Published by the National Vulnerability Database
Nov 14, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Reviewed
Nov 14, 2023
Last updated
Nov 15, 2023
Problem
DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of
typo3/html-sanitizer
.Solution
Update to
typo3/html-sanitizer
versions 1.5.3 or 2.1.4 that fix the problem described.Credits
Thanks to Yaniv Nizry and Niels Dossche who reported this issue, and to TYPO3 core & security team member Oliver Hader who fixed the issue.
References
masterminds/html5
References