Skip to content

Commit 99b1143

Browse files
committed
Mention new security issues fixed in 1.6.6 release.
1 parent 5d58ffa commit 99b1143

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

SECURITY.md

+2
Original file line numberDiff line numberDiff line change
@@ -31,3 +31,5 @@ These are the known CVEs reported for AntiSamy:
3131
* AntiSamy CVE #1 - CVE-2016-10006: XSS Bypass in AntiSamy before v1.5.5 - https://www.cvedetails.com/cve/CVE-2016-10006
3232
* AntiSamy CVE #2 - CVE-2017-14735: XSS via HTML5 Entities in AntiSamy before v1.5.7 - https://www.cvedetails.com/cve/CVE-2017-14735
3333
* AntiSamy CVE #3 - CVE-2021-35043: XSS via HTML attributes using &#00058 as replacement for : character before v1.6.4 - https://www.cvedetails.com/cve/CVE-2021-35043
34+
# AntiSamy CVEs #4 & #5 - We don't have CVEs yet for these. A vulnerability in a dependency was also found at the same time and fixed by upgrading to a fixed version of that dependency.
35+

0 commit comments

Comments
 (0)