cbcvebase.
CVE-2021-28957
published 2021-03-21

CVE-2021-28957: An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner…

PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
4.00%
89.4th percentile
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlxml< lxml 4.6.3-1 (bookworm)lxml 4.6.3-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
lxmllxml< 4.6.34.6.3
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.3-14.6.3-1
lxmllxml>= 0 < 4.6.34.6.3
msrccbl2_python-lxml_4.8.0-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_python-lxml_4.6.3-1_on_cbl_mariner_1.0
oraclezfs_storage_appliance_kit

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.