QID 981322
QID 981322: Python (pip) Security Update for feedparser (GHSA-4m72-rmm9-2qjr)
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4m72-rmm9-2qjr for updates pertaining to this vulnerability.
Vendor References
- GHSA-4m72-rmm9-2qjr -
github.com/advisories/GHSA-4m72-rmm9-2qjr
CVEs related to QID 981322
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4m72-rmm9-2qjr | feedparser |
|