OESA-2021-1178
Dashboard / Vulnerabilities / OESA-2021-1178
Summary: python-lxml security update
Details: The lxml XML toolkit is a Pythonic binding for the C libraries libxml2 and libxslt. It is unique in that it combines the speed and XML feature completeness of these libraries with the simplicity of a native Python API, mostly compatible but superior to the well-known ElementTree API. The latest release works with all CPython versions from 2.7 to 3.7. Security Fix(es): An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.(CVE-2021-28957)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1178, https://nvd.nist.gov/vuln/detail/CVE-2021-28957
Affected packages
Package
Name: python-lxml
Purl: pkg:rpm/openEuler/python-lxml&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
