CVE-2020-27783
published 2020-12-03CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
3.93%
89.2th percentile
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lxml | < lxml 4.6.2-1 (bookworm) | lxml 4.6.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lxml | lxml | >= 0 < 4.6.2-1 | 4.6.2-1 |
| lxml | lxml | >= 0 < 4.6.2-1 | 4.6.2-1 |
| lxml | lxml | >= 0 < 4.6.2-1 | 4.6.2-1 |
| lxml | lxml | >= 0 < 4.6.2-1 | 4.6.2-1 |
| lxml | lxml | >= 0 < 4.6.2 | 4.6.2 |
| lxml | lxml | >= 1.2 < 4.6.2 | 4.6.2 |
| msrc | cbl2_python-lxml_4.8.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python-lxml_4.6.3-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
lxml vulnerability
vendor_ubuntu·2020-12-11
CVE-2020-27783 lxml vulnerability
Title: lxml vulnerability
Summary: lxml could allow cross-site scripting (XSS) attacks.
USN-4666-1 partially fixed a vulnerability in lxml, but an additional patch was needed. This update provides
the corresponding additional patch in order to properly fix the vulnerability.
Original advisory details:
It was discovered that lxml incorrectly handled certain HTML.
An attacker could possibly use this issue to cross-site scripting (XSS) attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
lxml vulnerability
vendor_ubuntu·2020-12-09
CVE-2020-27783 lxml vulnerability
Title: lxml vulnerability
Summary: lxml could allow cross-site scripting (XSS) attacks.
It was discovered that lxml incorrectly handled certain HTML.
An attacker could possibly use this issue to cross-site scripting (XSS) attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers which caused different behaviors between the sanitizer and the user's page. A rem
vendor_msrc·2020-12-08·CVSS 6.1
CVE-2020-27783 [MEDIUM] CWE-79 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers which caused different behaviors between the sanitizer and the user's page. A rem
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information.
Red Hat
python-lxml: mXSS due to the use of improper parser
vendor_redhat·2020-10-18·CVSS 6.1
CVE-2020-27783 [MEDIUM] CWE-79 python-lxml: mXSS due to the use of improper parser
python-lxml: mXSS due to the use of improper parser
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
A Cross-site Scripting (XSS) vulnerability was found in the python-lxml's clean module. The module's parser did not properly imitate browsers, causing different behaviors between the sanitizer and the user's page. This flaw allows a remote attacker to run arbitrary HTML/JS code. The highest threat from this vulnerability is to confidentiality and integrity.
Package: python-lxml (Red Hat Enterprise Linux 5) - Out of support scope
Package: python-lxml (Red Hat Enterprise L
Debian
CVE-2020-27783: lxml - A XSS vulnerability was discovered in python-lxml's clean module. The module's p...
vendor_debian·2020·CVSS 6.1
CVE-2020-27783 [MEDIUM] CVE-2020-27783: lxml - A XSS vulnerability was discovered in python-lxml's clean module. The module's p...
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Scope: local
bookworm: resolved (fixed in 4.6.2-1)
bullseye: resolved (fixed in 4.6.2-1)
forky: resolved (fixed in 4.6.2-1)
sid: resolved (fixed in 4.6.2-1)
trixie: resolved (fixed in 4.6.2-1)
OSV
lxml vulnerable to Cross-site Scripting
osv·2021-01-07
CVE-2020-27783 [MEDIUM] lxml vulnerable to Cross-site Scripting
lxml vulnerable to Cross-site Scripting
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
GHSA
lxml vulnerable to Cross-site Scripting
ghsa·2021-01-07
CVE-2020-27783 [MEDIUM] CWE-79 lxml vulnerable to Cross-site Scripting
lxml vulnerable to Cross-site Scripting
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
OSV
CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module
osv·2020-12-03·CVSS 6.1
CVE-2020-27783 [MEDIUM] CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://advisory.checkmarx.net/advisory/CX-2020-4286https://bugzilla.redhat.com/show_bug.cgi?id=1901633https://lists.debian.org/debian-lts-announce/2020/12/msg00028.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKG67GPGTV23KADT4D4GK4RMHSO4CIQL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMHVKRUT22LVWNL3TB7HPSDHJT74Q3JK/https://security.netapp.com/advisory/ntap-20210521-0003/https://www.debian.org/security/2020/dsa-4810https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://advisory.checkmarx.net/advisory/CX-2020-4286https://bugzilla.redhat.com/show_bug.cgi?id=1901633https://lists.debian.org/debian-lts-announce/2020/12/msg00028.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JKG67GPGTV23KADT4D4GK4RMHSO4CIQL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMHVKRUT22LVWNL3TB7HPSDHJT74Q3JK/https://security.netapp.com/advisory/ntap-20210521-0003/https://www.debian.org/security/2020/dsa-4810https://www.oracle.com//security-alerts/cpujul2021.html
2020-12-03
Published