Cross-site scripting in lxml - CVE-2020-27783
Published: December 3, 2020 / Updated: December 6, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within lxml Python clean module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Arch Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openSUSE Leap
openEuler
lxml (Debian package)
py3-lxml (Alpine package)
python3-lxml (Ubuntu package)
python-lxml (Ubuntu package)
python-lxml
python3-lxml
python3-lxml-doc
python3-lxml-debuginfo
python3-lxml-debugsource
python-lxml-debugsource
python-lxml-debuginfo
python2-lxml-doc
python-lxml (Red Hat package)
python2-lxml
python-lxml-help
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Juniper Cloud Native Router
Junos cRPD
How to mitigate CVE-2020-27783
lxml (Debian package) - update to 4.3.2-1+deb10u1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
python3-lxml (Ubuntu package) - addressed in versions 2.3.2-1ubuntu0.4, 2.3.2-1ubuntu0.5, 3.5.0-1ubuntu0.2, 3.5.0-1ubuntu0.3, 4.2.1-1ubuntu0.2, 4.2.1-1ubuntu0.3, 4.5.0-1ubuntu0.1, 4.5.0-1ubuntu0.2, 4.5.2-1ubuntu0.1, 4.5.2-1ubuntu0.3
python-lxml (Ubuntu package) - addressed in versions 2.3.2-1ubuntu0.4, 2.3.2-1ubuntu0.5, 3.5.0-1ubuntu0.2, 3.5.0-1ubuntu0.3, 4.2.1-1ubuntu0.2, 4.2.1-1ubuntu0.3, 4.5.0-1ubuntu0.1, 4.5.0-1ubuntu0.2
python-lxml - update to 3.2.1-4.10
python3-lxml - addressed in versions 3.3.5-3.12.1, 3.6.1-3.3.1
python3-lxml-doc - addressed in versions 3.3.5-3.12.1, 4.0.0-150000.4.3.1
python3-lxml-debuginfo - update to 3.6.1-3.3.1
python3-lxml-debugsource - update to 3.6.1-3.3.1
python-lxml-debugsource - update to 3.6.1-8.5.1
python-lxml-debuginfo - update to 3.6.1-8.5.1
python-lxml - update to 3.6.1-8.5.1
python2-lxml-doc - update to 4.0.0-150000.4.3.1
python-lxml (Red Hat package) - update to 4.2.3-2.el8
python3-lxml - update to 4.2.5-4.el7
python-lxml - addressed in versions 4.4.1-5.fc32, 4.5.1-3.fc33
python-lxml - update to 4.5.2-2
python-lxml-debugsource - update to 4.5.2-2
python2-lxml - update to 4.5.2-2
python-lxml-debuginfo - update to 4.5.2-2
python3-lxml - update to 4.5.2-2
python-lxml-help - update to 4.5.2-2
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- Cross-site scripting in Python lxml module
- Arch Linux update for python-lxml
- Cross-site scripting in py3-lxml (Alpine package)
- Debian update for lxml
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 8 update for the python38:3.8 module
- Red Hat Enterprise Linux 8 update for python-lxml
- Multiple vulnerabilities in IBM Cloud Pak for Security
- SUSE update for python3-lxml
- SUSE update for python3-lxml
- SUSE update for python-lxml
- SUSE update for python-lxml
- Amazon Linux AMI update for python-lxml
- openEuler update for python-lxml
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Fedora EPEL 7 update for python3-lxml
- Ubuntu update for lxml
- Ubuntu update for lxml
- Fedora 33 update for python-lxml
- Fedora 32 update for python-lxml