[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Lxml - (bulletinjul2019)

ID: oval:org.secpod.oval:def:2105058Date: (C)2019-12-31   (M)2023-12-20
Class: PATCHFamily: unix




An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Internet Explorer. This is a similar issue to CVE-2014-3146.

Platform:
Sun Solaris 11
Product:
library/python/urllib3
library/python/urllib3-35
library/python/urllib3-34
library/python/urllib3-27
library/python/paramiko
library/python/paramiko-35
library/python/paramiko-34
library/python/paramiko-27
library/python/lxml
library/python/lxml-35
library/python/lxml-34
library/python/lxml-27
library/python/jinja2
library/python/jinja2-35
library/python/jinja2-34
library/python/jinja2-27
Reference:
bulletinjul2019
CVE-2018-19787
CVE-2018-19591
CVE    2
CVE-2018-19591
CVE-2018-19787
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies