CVE-2021-28957
21.03.2021, 05:15
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Vendor | Product | Version |
---|---|---|
lxml | lxml | 𝑥 < 4.6.3 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
netapp | snapcenter | - |
oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References