Описание
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
A Cross-site Scripting (XSS) vulnerability was found in the python-lxml's clean module. The module's parser did not properly imitate browsers, causing different behaviors between the sanitizer and the user's page. This flaw allows a remote attacker to run arbitrary HTML/JS code. The highest threat from this vulnerability is to confidentiality and integrity.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | python-lxml | Out of support scope | ||
Red Hat Enterprise Linux 6 | python-lxml | Out of support scope | ||
Red Hat Enterprise Linux 7 | python-lxml | Out of support scope | ||
Red Hat Enterprise Linux 9 | python-lxml | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-lxml | Out of support scope | ||
Red Hat OpenStack Platform 13 (Queens) | python-lxml | Will not fix | ||
Red Hat Enterprise Linux 8 | python27 | Fixed | RHSA-2021:1761 | 18.05.2021 |
Red Hat Enterprise Linux 8 | python38 | Fixed | RHSA-2021:1879 | 18.05.2021 |
Red Hat Enterprise Linux 8 | python-lxml | Fixed | RHSA-2021:1898 | 18.05.2021 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-babel | Fixed | RHSA-2021:3254 | 24.08.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
A XSS vulnerability was discovered in python-lxml's clean module. The ...
EPSS
6.1 Medium
CVSS3