SUSE-SU-2022:0895-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 17 Mar 2022, 14:38
Last modified:04 Feb 2026, 04:07

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Mar 2022, 14:38
Published
Vulnerability first disclosed
04 Feb 2026, 04:07
Last Modified
Vulnerability information updated

Description

Security update for python-lxml This update for python-lxml fixes the following issues: - CVE-2021-43818: Removed SVG image data URLs since they can embed script content (bsc#1193752). - CVE-2021-28957: Fixed a potential XSS due to improper input sanitization (bsc#1184177). - CVE-2020-27783: Fixed a potential XSS due to improper HTML parsing (bsc#1179534). - CVE-2018-19787: Fixed a potential XSS due to improper input sanitization (bsc#1118088).

Affected Systems

  • susepython-lxml&distro=HPE Helion OpenStack 8

    < 3.6.1-8.5.1

  • susepython-lxml&distro=SUSE Linux Enterprise Server 12 SP5

    < 3.6.1-8.5.1

  • susepython-lxml&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5

    < 3.6.1-8.5.1

  • susepython-lxml&distro=SUSE OpenStack Cloud 8

    < 3.6.1-8.5.1

  • susepython-lxml&distro=SUSE OpenStack Cloud Crowbar 8

    < 3.6.1-8.5.1

References (9)