First published: Sun Oct 18 2020(Updated: )
A Cross-site Scripting (XSS) vulnerability was found in the python-lxml's clean module. The module's parser did not properly imitate browsers, causing different behaviors between the sanitizer and the user's page. This flaw allows a remote attacker to run arbitrary HTML/JS code. The highest threat from this vulnerability is to confidentiality and integrity.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/lxml | <4.6.2 | 4.6.2 |
redhat/python-lxml | <0:4.2.3-2.el8 | 0:4.2.3-2.el8 |
redhat/rh-python38-babel | <0:2.7.0-12.el7 | 0:2.7.0-12.el7 |
redhat/rh-python38-python | <0:3.8.11-2.el7 | 0:3.8.11-2.el7 |
redhat/rh-python38-python-cryptography | <0:2.8-5.el7 | 0:2.8-5.el7 |
redhat/rh-python38-python-jinja2 | <0:2.10.3-6.el7 | 0:2.10.3-6.el7 |
redhat/rh-python38-python-lxml | <0:4.4.1-7.el7 | 0:4.4.1-7.el7 |
redhat/rh-python38-python-pip | <0:19.3.1-2.el7 | 0:19.3.1-2.el7 |
redhat/rh-python38-python-urllib3 | <0:1.25.7-7.el7 | 0:1.25.7-7.el7 |
Lxml Lxml | >=1.2<4.6.2 | |
Redhat Software Collections | ||
Redhat Enterprise Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Netapp Snapcenter | ||
Oracle Communications Offline Mediation Controller | =12.0.0.3.0 | |
Oracle ZFS Storage Appliance Kit | =8.8 | |
debian/lxml | 4.3.2-1+deb10u4 4.6.3+dfsg-0.1+deb11u1 4.9.2-1 4.9.3-1 | |
redhat/lxml | <4.6.2 | 4.6.2 |
IBM QRadar SIEM | <=7.5 - 7.5.0 UP8 IF01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-27783 is a Cross-site Scripting (XSS) vulnerability found in the python-lxml's clean module.
CVE-2020-27783 allows a remote attacker to run arbitrary HTML/JS code by exploiting the improper imitation of browsers in the module's parser.
The severity of CVE-2020-27783 is medium with a CVSS score of 6.1.
The python-lxml package version 0:4.2.3-2.el8 and the following rh-python38 packages are affected: rh-python38-babel, rh-python38-python, rh-python38-python-cryptography, rh-python38-python-jinja2, rh-python38-python-lxml, rh-python38-python-pip, rh-python38-python-urllib3.
To fix CVE-2020-27783, upgrade the python-lxml package to version 4.6.2 or higher and ensure the affected rh-python38 packages are updated to the fixed versions provided by Red Hat.