Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-lxml-docsUpgrade python-lxml-debuginfoUpgrade python-lxml | Mar 14, 2025 | May 14, 2014 |
| Debian | — | Upgrade lxml | Feb 20, 2019 | May 14, 2014 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-lxml | Feb 22, 2021 | May 14, 2014 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-lxml | Apr 30, 2021 | May 14, 2014 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-lxml | Nov 2, 2020 | May 14, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 15, 2014 |
| Suse | — | Upgrade python-lxml-docUpgrade python-lxml | Dec 18, 2015 | May 14, 2014 |
| Ubuntu | — | Upgrade python3-lxmlUpgrade python-lxml | Nov 8, 2024 | May 14, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub