HIGH · 8.2

CVE-2021-43818

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content ...

Vulnerability Description

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
LxmlLxml< 4.6.5
FedoraprojectFedora34
DebianDebian Linux9.0
NetappSolidfire-
NetappSolidfire Enterprise Sds-
NetappHci Storage Node Firmware-
NetappHci Storage Node-
OracleCommunications Cloud Native Core Binding Support Function22.1.3
OracleCommunications Cloud Native Core Network Exposure Function22.1.1
OracleCommunications Cloud Native Core Policy22.2.0
OracleHttp Server12.2.1.3.0
OracleZfs Storage Appliance Kit8.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-43818?

CVE-2021-43818 is a vulnerability with a CVSS score of 8.2 (HIGH). lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content ...

How severe is CVE-2021-43818?

CVE-2021-43818 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-43818?

Check the references section above for vendor advisories and patch information. Affected products include: Lxml Lxml, Fedoraproject Fedora, Debian Debian Linux, Netapp Solidfire, Netapp Solidfire Enterprise Sds.