CVE-2020-27783

Public on 2020-12-03
Modified on 2024-02-05
Description
A Cross-site Scripting (XSS) vulnerability was found in the python-lxml's clean module. The module's parser did not properly imitate browsers, causing different behaviors between the sanitizer and the user's page. This flaw allows a remote attacker to run arbitrary HTML/JS code. The highest threat from this vulnerability is to confidentiality and integrity.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 python-lxml 2023-03-17 ALAS-2023-1709 Fixed
HAQM Linux 2 - Core python-lxml 2021-06-16 ALAS2-2021-1666 Fixed
HAQM Linux 2023 python-lxml Not Affected

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NVD CVSSv2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N
NVD CVSSv3 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N