MGASA-2021-0246
Dashboard / Vulnerabilities / MGASA-2021-0246
Summary: Updated python-lxml packages fix a security vulnerability
Details: An XSS vulnerability was discovered in python-lxml’s clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML (CVE-2021-28957).
References: https://advisories.mageia.org/MGASA-2021-0246.html, https://bugs.mageia.org/show_bug.cgi?id=28983, https://lists.fedoraproject.org/archives/list/[email protected]/thread/3C2R44VDUY7FJVMAVRZ2WY7XYL4SVN45/, https://www.debian.org/security/2021/dsa-4880, https://ubuntu.com/security/notices/USN-4896-1
Affected packages
Package
Name: python-lxml
Purl: pkg:rpm/mageia/python-lxml?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
