OESA-2022-1482

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-1482
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-1482.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2022-1482
Upstream
Published
2022-01-07T11:03:26Z
Modified
2025-08-12T05:10:34.422866Z
Summary
python-lxml security update
Details

XML processing library combining libxml2/libxslt with the ElementTree API.

Security Fix(es):

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.(CVE-2021-43818)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/openEuler/python-lxml&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.2-4.oe1

Ecosystem specific

{
    "src": [
        "python-lxml-4.5.2-4.oe1.src.rpm"
    ],
    "noarch": [
        "python-lxml-help-4.5.2-4.oe1.noarch.rpm"
    ],
    "x86_64": [
        "python-lxml-debuginfo-4.5.2-4.oe1.x86_64.rpm",
        "python2-lxml-4.5.2-4.oe1.x86_64.rpm",
        "python3-lxml-4.5.2-4.oe1.x86_64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "python-lxml-debuginfo-4.5.2-4.oe1.aarch64.rpm",
        "python3-lxml-4.5.2-4.oe1.aarch64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.aarch64.rpm",
        "python2-lxml-4.5.2-4.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/openEuler/python-lxml&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.2-4.oe1

Ecosystem specific

{
    "src": [
        "python-lxml-4.5.2-4.oe1.src.rpm"
    ],
    "noarch": [
        "python-lxml-help-4.5.2-4.oe1.noarch.rpm"
    ],
    "x86_64": [
        "python-lxml-debuginfo-4.5.2-4.oe1.x86_64.rpm",
        "python3-lxml-4.5.2-4.oe1.x86_64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.x86_64.rpm",
        "python2-lxml-4.5.2-4.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "python2-lxml-4.5.2-4.oe1.aarch64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.aarch64.rpm",
        "python-lxml-debuginfo-4.5.2-4.oe1.aarch64.rpm",
        "python3-lxml-4.5.2-4.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / python-lxml

Package

Name
python-lxml
Purl
pkg:rpm/openEuler/python-lxml&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.2-4.oe1

Ecosystem specific

{
    "src": [
        "python-lxml-4.5.2-4.oe1.src.rpm"
    ],
    "noarch": [
        "python-lxml-help-4.5.2-4.oe1.noarch.rpm"
    ],
    "x86_64": [
        "python-lxml-debuginfo-4.5.2-4.oe1.x86_64.rpm",
        "python3-lxml-4.5.2-4.oe1.x86_64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.x86_64.rpm",
        "python2-lxml-4.5.2-4.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "python2-lxml-4.5.2-4.oe1.aarch64.rpm",
        "python-lxml-debugsource-4.5.2-4.oe1.aarch64.rpm",
        "python-lxml-debuginfo-4.5.2-4.oe1.aarch64.rpm",
        "python3-lxml-4.5.2-4.oe1.aarch64.rpm"
    ]
}