CVE-2020-27783
Summary
| CVE | CVE-2020-27783 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-03 17:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1901633 – (CVE-2020-27783) CVE-2020-27783 python-lxml: mXSS due to the use of improper parser |
MISC |
bugzilla.redhat.com |
Exploit, Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: python-lxml-4.4.1-5.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| advisory.checkmarx.net/advisory/CX-2020-4286 |
MISC |
advisory.checkmarx.net |
|
| Debian -- Security Information -- DSA-4810-1 lxml |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 33 Update: python-lxml-4.5.1-3.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| [SECURITY] [DLA 2467-2] lxml regression update |
MLIST |
lists.debian.org |
|
| CVE-2020-27783 lxml Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] Fedora 32 Update: python-lxml-4.4.1-5.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: python-lxml-4.5.1-3.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159227 Oracle Enterprise Linux Security Update for python-lxml (ELSA-2021-1898)
- 159342 Oracle Enterprise Linux Security Update for python27:2.7 (ELSA-2021-1761)
- 159460 Oracle Enterprise Linux Security Update for python38:3.8 (ELSA-2021-1879)
- 159768 Oracle Enterprise Linux Security Update for ol-automation-manager (ELSA-2022-9341)
- 239289 Red Hat Update for python-lxml (RHSA-2021:1898)
- 239292 Red Hat Update for python38:3.8 (RHSA-2021:1879)
- 239307 Red Hat Update for python27:2.7 (RHSA-2021:1761)
- 239580 Red Hat Update for rh-python38 (RHSA-2021:3254)
- 296069 Oracle Solaris 11.4 Support Repository Update (SRU) 31.88.5 Missing (CPUJAN2021)
- 352388 Amazon Linux Security Advisory for python-lxml: ALAS2-2021-1666
- 354846 Amazon Linux Security Advisory for python-lxml : ALAS-2023-1709
- 377332 Alibaba Cloud Linux Security Update for python-lxml (ALINUX3-SA-2022:0086)
- 377557 Alibaba Cloud Linux Security Update for python27:2.7 (ALINUX3-SA-2022:0112)
- 501364 Alpine Linux Security Update for py3-lxml
- 501679 Alpine Linux Security Update for py3-lxml
- 504329 Alpine Linux Security Update for py3-lxml
- 670202 EulerOS Security Update for python-lxml (EulerOS-SA-2021-1701)
- 670237 EulerOS Security Update for python-lxml (EulerOS-SA-2021-1839)
- 670673 EulerOS Security Update for python-lxml (EulerOS-SA-2021-2431)
- 751854 SUSE Enterprise Linux Security Update for python-lxml (SUSE-SU-2022:0803-1)
- 751858 OpenSUSE Security Update for python-lxml (openSUSE-SU-2022:0803-1)
- 751901 SUSE Enterprise Linux Security Update for python-lxml (SUSE-SU-2022:0895-1)
- 752637 SUSE Enterprise Linux Security Update for python3-lxml (SUSE-SU-2022:3461-1)
- 900214 CBL-Mariner Linux Security Update for python-lxml 4.2.4
- 901809 Common Base Linux Mariner (CBL-Mariner) Security Update for python-lxml (6807-1)
- 903431 Common Base Linux Mariner (CBL-Mariner) Security Update for python-lxml (4681)
- 940287 AlmaLinux Security Update for python38:3.8 (ALSA-2021:1879)
- 940311 AlmaLinux Security Update for python27:2.7 (ALSA-2021:1761)
- 960385 Rocky Linux Security Update for python38:3.8 (RLSA-2021:1879)
- 960420 Rocky Linux Security Update for python27:2.7 (RLSA-2021:1761)
- 960873 Rocky Linux Security Update for python-lxml (RLSA-2021:1898)
- 982397 Python (pip) Security Update for lxml (GHSA-pgww-xf46-h92r)