QID 980346

QID 980346: Python (pip) Security Update for lxml (GHSA-jq4v-f5q6-mjqq)

An XSS vulnerability was discovered in the python `lxml` clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in `lxml` 4.6.3.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-jq4v-f5q6-mjqq for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980346

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jq4v-f5q6-mjqq lxml URL Logo github.com/advisories/GHSA-jq4v-f5q6-mjqq