Cross-site scripting in lxml - CVE-2020-27783

 

Cross-site scripting in lxml - CVE-2020-27783

Published: December 3, 2020 / Updated: December 6, 2020


Vulnerability identifier: #VU48793
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-27783
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data within lxml Python clean module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

lxml
Arch Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openSUSE Leap
openEuler
lxml (Debian package)
py3-lxml (Alpine package)
python3-lxml (Ubuntu package)
python-lxml (Ubuntu package)
python-lxml
python3-lxml
python3-lxml-doc
python3-lxml-debuginfo
python3-lxml-debugsource
python-lxml-debugsource
python-lxml-debuginfo
python2-lxml-doc
python-lxml (Red Hat package)
python2-lxml
python-lxml-help
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Juniper Cloud Native Router
Junos cRPD

How to mitigate CVE-2020-27783

Install updates from vendor's website.

lxml - update to 4.6.2
lxml (Debian package) - update to 4.3.2-1+deb10u1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
python3-lxml (Ubuntu package) - addressed in versions 2.3.2-1ubuntu0.4, 2.3.2-1ubuntu0.5, 3.5.0-1ubuntu0.2, 3.5.0-1ubuntu0.3, 4.2.1-1ubuntu0.2, 4.2.1-1ubuntu0.3, 4.5.0-1ubuntu0.1, 4.5.0-1ubuntu0.2, 4.5.2-1ubuntu0.1, 4.5.2-1ubuntu0.3
python-lxml (Ubuntu package) - addressed in versions 2.3.2-1ubuntu0.4, 2.3.2-1ubuntu0.5, 3.5.0-1ubuntu0.2, 3.5.0-1ubuntu0.3, 4.2.1-1ubuntu0.2, 4.2.1-1ubuntu0.3, 4.5.0-1ubuntu0.1, 4.5.0-1ubuntu0.2
python-lxml - update to 3.2.1-4.10
python3-lxml - addressed in versions 3.3.5-3.12.1, 3.6.1-3.3.1
python3-lxml-doc - addressed in versions 3.3.5-3.12.1, 4.0.0-150000.4.3.1
python3-lxml-debuginfo - update to 3.6.1-3.3.1
python3-lxml-debugsource - update to 3.6.1-3.3.1
python-lxml-debugsource - update to 3.6.1-8.5.1
python-lxml-debuginfo - update to 3.6.1-8.5.1
python-lxml - update to 3.6.1-8.5.1
python2-lxml-doc - update to 4.0.0-150000.4.3.1
python-lxml (Red Hat package) - update to 4.2.3-2.el8
python3-lxml - update to 4.2.5-4.el7
python-lxml - addressed in versions 4.4.1-5.fc32, 4.5.1-3.fc33
python-lxml - update to 4.5.2-2
python-lxml-debugsource - update to 4.5.2-2
python2-lxml - update to 4.5.2-2
python-lxml-debuginfo - update to 4.5.2-2
python3-lxml - update to 4.5.2-2
python-lxml-help - update to 4.5.2-2
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

External References

Related Security Bulletins