Bypass of Cross-Site Scripting Protection in typo3/html-sanitizer
Published Sep 13, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.82%
Description
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and sanitized. This allows for a bypass of the cross-site scripting mechanism of `typo3/html-sanitizer`. This issue has been addressed in versions 1.0.7 and 2.0.16 of the `typo3/html-sanitizer` package. Users are advised to upgrade. There are no known workarounds for this issue.
Affected products
-
- Version >= 1.0.0, < 1.0.7StatusaffectedConstraints-
- Version >= 2.0.0, < 2.0.16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TYPO3 | Html-Sanitizer | n/a |
|
- ≥ 1.0.0 · < 1.0.7
- ≥ 2.0.0 · < 2.0.16
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6685 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2022-36020.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2022-36020.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/html-sanitizer/CVE-2022-36020.yaml
- https://github.com/TYPO3/html-sanitizer/commit/60bfdc7f9b394d0236e16ee4cea8372a7defa493 x_refsource_MISCPatchThird Party Advisory
- https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-47m6-46mj-p235 x_refsource_CONFIRMThird Party Advisory
- https://github.com/advisories/GHSA-47m6-46mj-p235 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36020
- https://packagist.org/packages/masterminds/html5 x_refsource_MISCThird Party Advisory
- https://packagist.org/packages/typo3/html-sanitizer x_refsource_MISCProductThird Party Advisory
- https://typo3.org/security/advisory/typo3-core-sa-2022-011
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6685 | Advisory | |
| https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2022-36020.yaml | ||
| https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2022-36020.yaml | ||
| https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/html-sanitizer/CVE-2022-36020.yaml | ||
| https://github.com/TYPO3/html-sanitizer/commit/60bfdc7f9b394d0236e16ee4cea8372a7defa493 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-47m6-46mj-p235 | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/advisories/GHSA-47m6-46mj-p235 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36020 | ||
| https://packagist.org/packages/masterminds/html5 | x_refsource_MISCThird Party Advisory | |
| https://packagist.org/packages/typo3/html-sanitizer | x_refsource_MISCProductThird Party Advisory | |
| https://typo3.org/security/advisory/typo3-core-sa-2022-011 |
Change history (0)
No recorded changes yet.