In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
| Software | From | Fixed in |
|---|---|---|
| mozilla / bleach | - | 3.1.1 |
| fedoraproject / fedora | 30 | 30.x |
| fedoraproject / fedora | 31 | 31.x |
| fedoraproject / fedora | 32 | 32.x |
bleach
|
- | 3.1.1 |