Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. lxml
  4. ›
  5. CVE-2020-27783

CVE-2020-27783: lxml vulnerable to Cross-site Scripting

January 7, 2021 (updated September 30, 2024)

A XSS vulnerability was discovered in python-lxml’s clean module. The module’s parser didn’t properly imitate browsers, which caused different behaviors between the sanitizer and the user’s page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.

References

  • advisory.checkmarx.net/advisory/CX-2020-4286
  • bugzilla.redhat.com/show_bug.cgi?id=1901633
  • github.com/advisories/GHSA-pgww-xf46-h92r
  • github.com/lxml/lxml
  • github.com/lxml/lxml/commit/a105ab8dc262ec6735977c25c13f0bdfcdec72a7
  • github.com/pypa/advisory-database/tree/main/vulns/lxml/PYSEC-2020-62.yaml
  • lists.debian.org/debian-lts-announce/2020/12/msg00028.html
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JKG67GPGTV23KADT4D4GK4RMHSO4CIQL
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TMHVKRUT22LVWNL3TB7HPSDHJT74Q3JK
  • nvd.nist.gov/vuln/detail/CVE-2020-27783
  • pypi.org/project/lxml
  • security.netapp.com/advisory/ntap-20210521-0003
  • snyk.io/vuln/SNYK-PYTHON-LXML-1047473
  • www.debian.org/security/2020/dsa-4810
  • www.oracle.com//security-alerts/cpujul2021.html

Code Behaviors & Features

Detect and mitigate CVE-2020-27783 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.6.2

Fixed versions

  • 4.6.2

Solution

Upgrade to version 4.6.2 or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

pypi/lxml/CVE-2020-27783.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:16 +0000.