svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the svg-sanitizer library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.
svg-sanitizer
{ "ubuntu_priority": "medium" }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "spip", "binary_version": "4.3.1+dfsg-1ubuntu0.1" } ], "ubuntu_priority": "medium" }