First published: Mon May 02 2022(Updated: )
lxml is an XML processing library providing access to libxml2 and libxslt libraries using the Python ElementTree API.<br>Security Fix(es):<br><li> python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-python38-python | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-lxml | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-pip | <19.3.1-3.el7 | 19.3.1-3.el7 |
redhat/rh-python38-python | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debug | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debuginfo | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-devel | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-idle | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-libs | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-lxml | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-lxml-debuginfo | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-pip | <19.3.1-3.el7 | 19.3.1-3.el7 |
redhat/rh-python38-python-pip-wheel | <19.3.1-3.el7 | 19.3.1-3.el7 |
redhat/rh-python38-python-rpm-macros | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-srpm-macros | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-test | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-tkinter | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debug | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debuginfo | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-devel | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-idle | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-libs | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-lxml-debuginfo | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-test | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-tkinter | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debug | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-debuginfo | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-devel | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-idle | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-libs | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-lxml | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-lxml-debuginfo | <4.4.1-8.el7 | 4.4.1-8.el7 |
redhat/rh-python38-python-test | <3.8.13-1.el7 | 3.8.13-1.el7 |
redhat/rh-python38-python-tkinter | <3.8.13-1.el7 | 3.8.13-1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1664 is classified as important due to potential security risks associated with the vulnerability.
To fix RHSA-2022:1664, update the affected packages to the recommended versions: rh-python38-python-3.8.13-1.el7 and rh-python38-python-lxml-4.4.1-8.el7.
RHSA-2022:1664 addresses a security flaw in python-lxml that allows crafted HTML Cleaner scripts with SVG to pass through.
Affected packages include rh-python38-python, rh-python38-python-lxml, and rh-python38-python-pip in their respective versions.
Yes, RHSA-2022:1664 is directly related to CVE-2021-43818 which describes the vulnerability in HTML Cleaner.