QID 982397
QID 982397: Python (pip) Security Update for lxml (GHSA-pgww-xf46-h92r)
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pgww-xf46-h92r for updates pertaining to this vulnerability.
Vendor References
- GHSA-pgww-xf46-h92r -
github.com/advisories/GHSA-pgww-xf46-h92r
CVEs related to QID 982397
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pgww-xf46-h92r | lxml |
|