MGASA-2018-0497

Source
https://advisories.mageia.org/MGASA-2018-0497.html
Import Source
https://advisories.mageia.org/MGASA-2018-0497.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0497
Related
Published
2018-12-31T22:42:09Z
Modified
2018-12-31T22:15:09Z
Summary
Updated python-lxml packages fix security vulnerability
Details

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer (CVE-2018-19787).

References
Credits

Affected packages

Mageia:6 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/mageia/python-lxml?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.5-1.mga6

Ecosystem specific

{
    "section": "core"
}