cbcvebase.
CVE-2021-28957
published 2021-03-21

CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlxml< lxml 4.6.3-1 (bookworm)lxml 4.6.3-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
lxmllxml< 4.6.34.6.3
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.34.6.3
msrccbl2_python-lxml_4.8.0-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_python-lxml_4.6.3-1_on_cbl_mariner_1.0
oraclezfs_storage_appliance_kit

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM