OESA-2021-1068
Dashboard / Vulnerabilities / OESA-2021-1068
Summary: python-lxml security update
Details: The lxml XML toolkit is a Pythonic binding for the C libraries libxml2 and libxslt. It is unique in that it combines the speed and XML feature completeness of these libraries with the simplicity of a native Python API, mostly compatible but superior to the well-known ElementTree API. The latest release works with all CPython versions from 2.7 to 3.7. Security Fix(es): A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.(CVE-2020-27783)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1068, https://nvd.nist.gov/vuln/detail/CVE-2020-27783
Affected packages
Package
Name: python-lxml
Purl: pkg:rpm/openEuler/python-lxml&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
