CVE-2021-43818 describes a vulnerability in the lxml Python library, specifically its HTML Cleaner, which allows crafted script content to bypass sanitization, including scripts embedded in SVG files via data URIs. This affects various products incorporating lxml, such as Debian, Fedora, NetApp, and Oracle. Rated with a CVSS score of 7.1 (HIGH), this vulnerability has a network attack vector and low attack complexity, requiring user interaction. Successful exploitation could lead to low impact on confidentiality, integrity, and availability, indicating potential cross-site scripting (XSS) scenarios. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While community discussion and media coverage are minimal, users are advised to upgrade to lxml version 4.6.5 to patch this vulnerability, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.6.5CPE matchmatch criteria | cpe:2.3:a:lxml:lxml:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
HTML Cleaner allows crafted and SVG embedded scripts to pass through
Dec 14, 2021lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through
Dec 13, 2021python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
Dec 12, 2021