emacs-bug-tracker
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#47319: closed (python-lxml is vulnerable to CVE-2021-28957)


From: GNU bug Tracking System
Subject: bug#47319: closed (python-lxml is vulnerable to CVE-2021-28957)
Date: Wed, 23 Mar 2022 02:34:02 +0000

Your message dated Tue, 22 Mar 2022 22:32:52 -0400
with message-id <874k3p1jqj.fsf@gmail.com>
and subject line Re: bug#47319: python-lxml is vulnerable to CVE-2021-28957
has caused the debbugs.gnu.org bug report #47319,
regarding python-lxml is vulnerable to CVE-2021-28957
to be marked as done.

(If you believe you have received this mail in error, please contact
help-debbugs@gnu.org.)


-- 
47319: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=47319
GNU Bug Tracking System
Contact help-debbugs@gnu.org with problems
--- Begin Message --- Subject: python-lxml is vulnerable to CVE-2021-28957 Date: Mon, 22 Mar 2021 15:09:24 +0100 User-agent: Evolution 3.34.2
CVE-2021-28957  21.03.21 06:15
lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in
html/defs.py) for later use in input sanitization, but does not do the
same for the HTML5 formaction attribute.

Upstream fixed it in 4.6.3 (
https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d
), so we should probably upgrade to that.

Has lots of dependents so I suppose it needs grafting? Is that useful
and does it work for Python packages?

Léo

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---
--- Begin Message --- Subject: Re: bug#47319: python-lxml is vulnerable to CVE-2021-28957 Date: Tue, 22 Mar 2022 22:32:52 -0400 User-agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux)
Hi,

Léo Le Bouter <lle-bout@zaclys.net> writes:

> CVE-2021-28957        21.03.21 06:15
> lxml 4.6.2 places the HTML action attribute into defs.link_attrs (in
> html/defs.py) for later use in input sanitization, but does not do the
> same for the HTML5 formaction attribute.
>
> Upstream fixed it in 4.6.3 (
> https://github.com/lxml/lxml/commit/2d01a1ba8984e0483ce6619b972832377f208a0d
> ), so we should probably upgrade to that.

This is the current version in Guix.

Closing; thanks!

Maxim


--- End Message ---

reply via email to

[Prev in Thread] Current Thread [Next in Thread]