Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6806.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-6806
Upstream
Published
2018-12-02T10:29:00Z
Modified
2026-04-01T05:21:20.523172Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
CVE-2018-19787 affecting package python-lxml for versions less than 4.8.0-1
Details

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

References

Affected packages

Azure Linux:2 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/azure-linux/python-lxml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-6806.json"