CVE-2021-28957
Last modified
CVE-2021-28957 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. EPSS estimates a 4.00% chance of exploitation in the next 30 days.
Description
An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lxml | Lxml | < 4.6.3 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 33 |
| Fedoraproject | Fedora | 34 |
| Netapp | Snapcenter | All versions |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
References
- https://bugs.launchpad.net/lxml/+bug/1888153Exploit, Issue Tracking, Third Party Advisory
- https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999Patch, Third Party Advisory
- https://github.com/lxml/lxml/pull/316/commits/10ec1b4e9f93713513a3264ed6158af22492f270Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00031.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210521-0004/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4880Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://bugs.launchpad.net/lxml/+bug/1888153Exploit, Issue Tracking, Third Party Advisory
- https://github.com/lxml/lxml/commit/a5f9cb52079dc57477c460dbe6ba0f775e14a999Patch, Third Party Advisory
- https://github.com/lxml/lxml/pull/316/commits/10ec1b4e9f93713513a3264ed6158af22492f270Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00031.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202208-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210521-0004/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4880Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28957?
How severe is CVE-2021-28957?
How do I fix CVE-2021-28957?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-28951An issue was discovered in fs/io_uring.c in the Linux kernel…5.5
- CVE-2021-28952An issue was discovered in the Linux kernel through 5.11.8. …7.8
- CVE-2021-28953The unofficial C/C++ Advanced Lint extension before 1.9.0 fo…7.8
- CVE-2021-28954In Chris Walz bit before 1.0.5 on Windows, attackers can run…7.8
- CVE-2021-28955git-bug before 0.7.2 has an Uncontrolled Search Path Element…9.8
- CVE-2021-28956The unofficial vscode-sass-lint (aka Sass Lint) extension th…8.8
- CVE-2021-28958Zoho ManageEngine ADSelfService Plus through 6101 is vulnera…9.8
- CVE-2021-28959Zoho ManageEngine Eventlog Analyzer through 12147 is vulnera…9.8
- CVE-2021-28960Zoho ManageEngine Desktop Central before build 10.0.683 allo…9.8
- CVE-2021-28961applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua …8.8
- CVE-2021-28962Stormshield Network Security (SNS) before 4.2.2 allows a rea…7.2
- CVE-2021-28963Shibboleth Service Provider before 3.2.1 allows content inje…5.3
Are you affected by CVE-2021-28957?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
