MEDIUM 6.1 Microsoft

CVE-2021-23980

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

Microsoft Security Update 2023-Feb: A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

Affected Products

References

Published: 2023-02-14 · Source: Microsoft · Feed updated: 2026-08-20
This medium severity vulnerability with a CVSS score of 6.1 was published on 2023-02-14 via Microsoft. Affected: cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0, azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.