SUSE-SU-2022:0803-1
Dashboard / Vulnerabilities / SUSE-SU-2022:0803-1
SUSE-SU-2022:0803-1
Summary: Security update for python-lxml
Details: This update for python-lxml fixes the following issues: - CVE-2018-19787: Fixed XSS vulnerability via unescaped URL (bsc#1118088). - CVE-2021-28957: Fixed XSS vulnerability ia HTML5 attributes unescaped (bsc#1184177). - CVE-2021-43818: Fixed XSS vulnerability via script content in SVG images using data URIs (bnc#1193752). - CVE-2020-27783: Fixed mutation XSS with improper parser use (bnc#1179534).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20220803-1/, https://bugzilla.suse.com/1118088, https://bugzilla.suse.com/1179534, https://bugzilla.suse.com/1184177, https://bugzilla.suse.com/1193752, https://www.suse.com/security/cve/CVE-2018-19787, https://www.suse.com/security/cve/CVE-2020-27783, https://www.suse.com/security/cve/CVE-2021-28957, https://www.suse.com/security/cve/CVE-2021-43818
Affected packages
Package
Name: python-lxml
Purl: pkg:rpm/suse/python-lxml&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
