Lucene search

K
osvGoogleOSV:USN-4666-2
HistoryDec 11, 2020 - 12:39 a.m.

lxml vulnerability

2020-12-1100:39:06
Google
osv.dev
7

0.004 Low

EPSS

Percentile

73.0%

USN-4666-1 partially fixed a vulnerability in lxml, but an additional patch was needed. This update provides
the corresponding additional patch in order to properly fix the vulnerability.

Original advisory details:

It was discovered that lxml incorrectly handled certain HTML.
An attacker could possibly use this issue to cross-site scripting (XSS) attacks.