QID 980346
QID 980346: Python (pip) Security Update for lxml (GHSA-jq4v-f5q6-mjqq)
An XSS vulnerability was discovered in the python `lxml` clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in `lxml` 4.6.3.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jq4v-f5q6-mjqq for updates pertaining to this vulnerability.
Vendor References
- GHSA-jq4v-f5q6-mjqq -
github.com/advisories/GHSA-jq4v-f5q6-mjqq
CVEs related to QID 980346
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jq4v-f5q6-mjqq | lxml |
|