In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.
[
{
"digest": {
"function_hash": "327506727195512130857608281471890945436",
"length": 1498.0
},
"id": "CVE-2020-4070-27bf7adc",
"signature_version": "v1",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java",
"function": "parseURL"
},
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"287126531491259831142828594517899965709",
"166151882237851564633381564464035597352",
"217623342706874349683039718344875380745",
"25486391784260251365600363288280579394"
],
"threshold": 0.9
},
"id": "CVE-2020-4070-dd4b0a2a",
"signature_version": "v1",
"target": {
"file": "org/w3c/css/css/StyleSheetParser.java"
},
"source": "https://github.com/w3c/css-validator/commit/e5c09a9119167d3064db786d5f00d730b584a53b",
"deprecated": false,
"signature_type": "Line"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-4070.json"