ALT-PU-2021-1429-1
Package python3-module-lxml updated to version 4.6.2-alt1 for branch sisyphus in task 267259.
Closed vulnerabilities
Published: 2020-12-03
BDU:2021-03620
Уязвимость модуля clean библиотеки для обработки разметки XML и HTML Lxml, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
Severity: MEDIUM (6.1)
Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
Published: 2020-12-03
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-27783
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Severity: MEDIUM (6.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- https://advisory.checkmarx.net/advisory/CX-2020-4286
- https://advisory.checkmarx.net/advisory/CX-2020-4286
- https://bugzilla.redhat.com/show_bug.cgi?id=1901633
- https://bugzilla.redhat.com/show_bug.cgi?id=1901633
- [debian-lts-announce] 20201218 [SECURITY] [DLA 2467-2] lxml regression update
- [debian-lts-announce] 20201218 [SECURITY] [DLA 2467-2] lxml regression update
- FEDORA-2020-307946cfb6
- FEDORA-2020-307946cfb6
- FEDORA-2020-0e055ea503
- FEDORA-2020-0e055ea503
- https://security.netapp.com/advisory/ntap-20210521-0003/
- https://security.netapp.com/advisory/ntap-20210521-0003/
- DSA-4810
- DSA-4810
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html