Wind River Support Network

HomeDefectsLIN1019-6260
Fixed

LIN1019-6260 : Security Advisory - python-lxml - CVE-2021-28957

Created: Mar 21, 2021    Updated: Jun 6, 2021
Resolved Date: Jun 6, 2021
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

lxml 4.6.2 allows XSS. It places the HTML action attribute into defs.link_attrs (in html/defs.py) for later use in input sanitization, but does not do the same for the HTML5 formaction attribute.

CREATE(Triage):(User=admin) [CVE-2021-28957|https://nvd.nist.gov/vuln/detail/CVE-2021-28957]

CVEs


Live chat
Online