CVE-2020-27783
03.12.2020, 17:15
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.
Vendor | Product | Version |
---|---|---|
lxml | lxml | 1.2 ≤ 𝑥 < 4.6.2 |
redhat | software_collections | - |
redhat | enterprise_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
netapp | snapcenter | - |
oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References