Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-27783

Опубликовано: 03 дек. 2020
Источник: debian
EPSS Низкий

Описание

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxmlfixed4.6.2-1package

Примечания

  • https://github.com/lxml/lxml/commit/89e7aad6e7ff9ecd88678ff25f885988b184b26e (lxml-4.6.1)

  • https://github.com/lxml/lxml/commit/a105ab8dc262ec6735977c25c13f0bdfcdec72a7 (lxml-4.6.2)

EPSS

Процентиль: 76%
0.01026
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
redhat
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
nvd
больше 4 лет назад

A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

CVSS3: 6.1
msrc
почти 4 года назад

Описание отсутствует

suse-cvrf
больше 2 лет назад

Security update for python3-lxml

EPSS

Процентиль: 76%
0.01026
Низкий