Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-28957

Опубликовано: 21 мар. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

РелизСтатусПримечание
bionic

released

4.2.1-1ubuntu0.4
devel

not-affected

4.6.3-1
esm-infra-legacy/trusty

not-affected

3.3.3-1ubuntu0.2+esm3
esm-infra/bionic

not-affected

4.2.1-1ubuntu0.4
esm-infra/focal

not-affected

4.5.0-1ubuntu0.3
esm-infra/xenial

not-affected

3.5.0-1ubuntu0.4
focal

released

4.5.0-1ubuntu0.3
groovy

released

4.5.2-1ubuntu0.4
precise/esm

ignored

trusty

ignored

end of standard support

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
около 4 лет назад

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVSS3: 6.1
nvd
около 4 лет назад

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

CVSS3: 6.1
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 6.1
debian
около 4 лет назад

An XSS vulnerability was discovered in python-lxml's clean module vers ...

suse-cvrf
больше 2 лет назад

Security update for python3-lxml

4.3 Medium

CVSS2

6.1 Medium

CVSS3