First published: Sun Mar 21 2021(Updated: )
A flaw was found in python-lxml. The HTML5 formaction attribute is not input sanitized like the HTML action attribute is which can lead to a Cross-Site Scripting attack (XSS) when an application uses python-lxml to sanitize user inputs. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/lxml | <4.6.3 | 4.6.3 |
redhat/python-lxml | <0:4.2.3-3.el8 | 0:4.2.3-3.el8 |
redhat/rh-python38-babel | <0:2.7.0-12.el7 | 0:2.7.0-12.el7 |
redhat/rh-python38-python | <0:3.8.11-2.el7 | 0:3.8.11-2.el7 |
redhat/rh-python38-python-cryptography | <0:2.8-5.el7 | 0:2.8-5.el7 |
redhat/rh-python38-python-jinja2 | <0:2.10.3-6.el7 | 0:2.10.3-6.el7 |
redhat/rh-python38-python-lxml | <0:4.4.1-7.el7 | 0:4.4.1-7.el7 |
redhat/rh-python38-python-pip | <0:19.3.1-2.el7 | 0:19.3.1-2.el7 |
redhat/rh-python38-python-urllib3 | <0:1.25.7-7.el7 | 0:1.25.7-7.el7 |
debian/lxml | 4.3.2-1+deb10u4 4.6.3+dfsg-0.1+deb11u1 4.9.2-1 4.9.3-1 | |
debian/lxml | <=4.3.2-1+deb10u2<=4.3.2-1<=4.6.2-1 | 4.6.3-1 4.3.2-1+deb10u3 |
Lxml Lxml | <4.6.3 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Netapp Snapcenter | ||
Oracle ZFS Storage Appliance Kit | =8.8 | |
redhat/python-lxml | <4.6.3 | 4.6.3 |
<4.6.3 | ||
=9.0 | ||
=10.0 | ||
=33 | ||
=34 | ||
=8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-28957 is an XSS vulnerability in the python `lxml` clean module versions before 4.6.3.
CVE-2021-28957 allows a remote attacker to bypass the sanitizer by exploiting the `formaction` attribute in the HTML5 form.
The python `lxml` clean module versions before 4.6.3 are affected by CVE-2021-28957.
CVE-2021-28957 has a severity rating of 6.1 (high).
To fix CVE-2021-28957, upgrade to python `lxml` clean module version 4.6.3 or later.