Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-43818

lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch. There are no known workarounds available.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.6%
CVSS Severity
CVSS v3 Score 8.2
CVSS v2 Score 6.8
References
Products affected by CVE-2021-43818
  • Lxml » Lxml » Version: 0.5
    cpe:2.3:a:lxml:lxml:0.5
  • Lxml » Lxml » Version: 0.5.1
    cpe:2.3:a:lxml:lxml:0.5.1
  • Lxml » Lxml » Version: 0.6
    cpe:2.3:a:lxml:lxml:0.6
  • Lxml » Lxml » Version: 0.7
    cpe:2.3:a:lxml:lxml:0.7
  • Lxml » Lxml » Version: 0.8
    cpe:2.3:a:lxml:lxml:0.8
  • Lxml » Lxml » Version: 0.9
    cpe:2.3:a:lxml:lxml:0.9
  • Lxml » Lxml » Version: 0.9.1
    cpe:2.3:a:lxml:lxml:0.9.1
  • Lxml » Lxml » Version: 0.9.2
    cpe:2.3:a:lxml:lxml:0.9.2
  • Lxml » Lxml » Version: 1.0
    cpe:2.3:a:lxml:lxml:1.0
  • Lxml » Lxml » Version: 1.0.1
    cpe:2.3:a:lxml:lxml:1.0.1
  • Lxml » Lxml » Version: 1.0.2
    cpe:2.3:a:lxml:lxml:1.0.2
  • Lxml » Lxml » Version: 1.0.3
    cpe:2.3:a:lxml:lxml:1.0.3
  • Lxml » Lxml » Version: 1.0.4
    cpe:2.3:a:lxml:lxml:1.0.4
  • Lxml » Lxml » Version: 1.1
    cpe:2.3:a:lxml:lxml:1.1
  • Lxml » Lxml » Version: 1.1.1
    cpe:2.3:a:lxml:lxml:1.1.1
  • Lxml » Lxml » Version: 1.1.2
    cpe:2.3:a:lxml:lxml:1.1.2
  • Lxml » Lxml » Version: 1.2
    cpe:2.3:a:lxml:lxml:1.2
  • Lxml » Lxml » Version: 1.2.1
    cpe:2.3:a:lxml:lxml:1.2.1
  • Lxml » Lxml » Version: 1.3
    cpe:2.3:a:lxml:lxml:1.3
  • Lxml » Lxml » Version: 1.3.1
    cpe:2.3:a:lxml:lxml:1.3.1
  • Lxml » Lxml » Version: 1.3.2
    cpe:2.3:a:lxml:lxml:1.3.2
  • Lxml » Lxml » Version: 1.3.3
    cpe:2.3:a:lxml:lxml:1.3.3
  • Lxml » Lxml » Version: 1.3.4
    cpe:2.3:a:lxml:lxml:1.3.4
  • Lxml » Lxml » Version: 1.3.5
    cpe:2.3:a:lxml:lxml:1.3.5
  • Lxml » Lxml » Version: 1.3.6
    cpe:2.3:a:lxml:lxml:1.3.6
  • Lxml » Lxml » Version: 2.0
    cpe:2.3:a:lxml:lxml:2.0
  • Lxml » Lxml » Version: 2.0.1
    cpe:2.3:a:lxml:lxml:2.0.1
  • Lxml » Lxml » Version: 2.0.10
    cpe:2.3:a:lxml:lxml:2.0.10
  • Lxml » Lxml » Version: 2.0.11
    cpe:2.3:a:lxml:lxml:2.0.11
  • Lxml » Lxml » Version: 2.0.2
    cpe:2.3:a:lxml:lxml:2.0.2
  • Lxml » Lxml » Version: 2.0.3
    cpe:2.3:a:lxml:lxml:2.0.3
  • Lxml » Lxml » Version: 2.0.4
    cpe:2.3:a:lxml:lxml:2.0.4
  • Lxml » Lxml » Version: 2.0.5
    cpe:2.3:a:lxml:lxml:2.0.5
  • Lxml » Lxml » Version: 2.0.6
    cpe:2.3:a:lxml:lxml:2.0.6
  • Lxml » Lxml » Version: 2.0.7
    cpe:2.3:a:lxml:lxml:2.0.7
  • Lxml » Lxml » Version: 2.0.8
    cpe:2.3:a:lxml:lxml:2.0.8
  • Lxml » Lxml » Version: 2.0.9
    cpe:2.3:a:lxml:lxml:2.0.9
  • Lxml » Lxml » Version: 2.1
    cpe:2.3:a:lxml:lxml:2.1
  • Lxml » Lxml » Version: 2.1.1
    cpe:2.3:a:lxml:lxml:2.1.1
  • Lxml » Lxml » Version: 2.1.2
    cpe:2.3:a:lxml:lxml:2.1.2
  • Lxml » Lxml » Version: 2.1.3
    cpe:2.3:a:lxml:lxml:2.1.3
  • Lxml » Lxml » Version: 2.1.4
    cpe:2.3:a:lxml:lxml:2.1.4
  • Lxml » Lxml » Version: 2.1.5
    cpe:2.3:a:lxml:lxml:2.1.5
  • Lxml » Lxml » Version: 2.2
    cpe:2.3:a:lxml:lxml:2.2
  • Lxml » Lxml » Version: 2.2.1
    cpe:2.3:a:lxml:lxml:2.2.1
  • Lxml » Lxml » Version: 2.2.2
    cpe:2.3:a:lxml:lxml:2.2.2
  • Lxml » Lxml » Version: 2.2.3
    cpe:2.3:a:lxml:lxml:2.2.3
  • Lxml » Lxml » Version: 2.2.4
    cpe:2.3:a:lxml:lxml:2.2.4
  • Lxml » Lxml » Version: 2.2.5
    cpe:2.3:a:lxml:lxml:2.2.5
  • Lxml » Lxml » Version: 2.2.6
    cpe:2.3:a:lxml:lxml:2.2.6
  • Lxml » Lxml » Version: 2.2.7
    cpe:2.3:a:lxml:lxml:2.2.7
  • Lxml » Lxml » Version: 2.2.8
    cpe:2.3:a:lxml:lxml:2.2.8
  • Lxml » Lxml » Version: 2.3
    cpe:2.3:a:lxml:lxml:2.3
  • Lxml » Lxml » Version: 2.3.1
    cpe:2.3:a:lxml:lxml:2.3.1
  • Lxml » Lxml » Version: 2.3.2
    cpe:2.3:a:lxml:lxml:2.3.2
  • Lxml » Lxml » Version: 2.3.3
    cpe:2.3:a:lxml:lxml:2.3.3
  • Lxml » Lxml » Version: 2.3.4
    cpe:2.3:a:lxml:lxml:2.3.4
  • Lxml » Lxml » Version: 2.3.5
    cpe:2.3:a:lxml:lxml:2.3.5
  • Lxml » Lxml » Version: 2.3.6
    cpe:2.3:a:lxml:lxml:2.3.6
  • Lxml » Lxml » Version: 3.0
    cpe:2.3:a:lxml:lxml:3.0
  • Lxml » Lxml » Version: 3.0.1
    cpe:2.3:a:lxml:lxml:3.0.1
  • Lxml » Lxml » Version: 3.0.2
    cpe:2.3:a:lxml:lxml:3.0.2
  • Lxml » Lxml » Version: 3.1
    cpe:2.3:a:lxml:lxml:3.1
  • Lxml » Lxml » Version: 3.1.0
    cpe:2.3:a:lxml:lxml:3.1.0
  • Lxml » Lxml » Version: 3.1.1
    cpe:2.3:a:lxml:lxml:3.1.1
  • Lxml » Lxml » Version: 3.1.2
    cpe:2.3:a:lxml:lxml:3.1.2
  • Lxml » Lxml » Version: 3.2.0
    cpe:2.3:a:lxml:lxml:3.2.0
  • Lxml » Lxml » Version: 3.2.1
    cpe:2.3:a:lxml:lxml:3.2.1
  • Lxml » Lxml » Version: 3.2.2
    cpe:2.3:a:lxml:lxml:3.2.2
  • Lxml » Lxml » Version: 3.2.3
    cpe:2.3:a:lxml:lxml:3.2.3
  • Lxml » Lxml » Version: 3.2.4
    cpe:2.3:a:lxml:lxml:3.2.4
  • Lxml » Lxml » Version: 3.2.5
    cpe:2.3:a:lxml:lxml:3.2.5
  • Lxml » Lxml » Version: 3.3.0
    cpe:2.3:a:lxml:lxml:3.3.0
  • Lxml » Lxml » Version: 3.3.1
    cpe:2.3:a:lxml:lxml:3.3.1
  • Lxml » Lxml » Version: 3.3.2
    cpe:2.3:a:lxml:lxml:3.3.2
  • Lxml » Lxml » Version: 3.3.3
    cpe:2.3:a:lxml:lxml:3.3.3
  • Lxml » Lxml » Version: 3.3.4
    cpe:2.3:a:lxml:lxml:3.3.4
  • Lxml » Lxml » Version: 3.3.5
    cpe:2.3:a:lxml:lxml:3.3.5
  • Lxml » Lxml » Version: 3.3.6
    cpe:2.3:a:lxml:lxml:3.3.6
  • Lxml » Lxml » Version: 3.4.0
    cpe:2.3:a:lxml:lxml:3.4.0
  • Lxml » Lxml » Version: 3.4.1
    cpe:2.3:a:lxml:lxml:3.4.1
  • Lxml » Lxml » Version: 3.4.2
    cpe:2.3:a:lxml:lxml:3.4.2
  • Lxml » Lxml » Version: 3.4.3
    cpe:2.3:a:lxml:lxml:3.4.3
  • Lxml » Lxml » Version: 3.4.4
    cpe:2.3:a:lxml:lxml:3.4.4
  • Lxml » Lxml » Version: 3.5.0
    cpe:2.3:a:lxml:lxml:3.5.0
  • Lxml » Lxml » Version: 3.6.0
    cpe:2.3:a:lxml:lxml:3.6.0
  • Lxml » Lxml » Version: 3.6.1
    cpe:2.3:a:lxml:lxml:3.6.1
  • Lxml » Lxml » Version: 3.6.2
    cpe:2.3:a:lxml:lxml:3.6.2
  • Lxml » Lxml » Version: 3.6.3
    cpe:2.3:a:lxml:lxml:3.6.3
  • Lxml » Lxml » Version: 3.6.4
    cpe:2.3:a:lxml:lxml:3.6.4
  • Lxml » Lxml » Version: 3.7.0
    cpe:2.3:a:lxml:lxml:3.7.0
  • Lxml » Lxml » Version: 3.7.1
    cpe:2.3:a:lxml:lxml:3.7.1
  • Lxml » Lxml » Version: 3.7.2
    cpe:2.3:a:lxml:lxml:3.7.2
  • Lxml » Lxml » Version: 3.8.0
    cpe:2.3:a:lxml:lxml:3.8.0
  • Lxml » Lxml » Version: 4.0.0
    cpe:2.3:a:lxml:lxml:4.0.0
  • Lxml » Lxml » Version: 4.1.0
    cpe:2.3:a:lxml:lxml:4.1.0
  • Lxml » Lxml » Version: 4.1.1
    cpe:2.3:a:lxml:lxml:4.1.1
  • Lxml » Lxml » Version: 4.2.0
    cpe:2.3:a:lxml:lxml:4.2.0
  • Lxml » Lxml » Version: 4.2.1
    cpe:2.3:a:lxml:lxml:4.2.1
  • Lxml » Lxml » Version: 4.2.2
    cpe:2.3:a:lxml:lxml:4.2.2
  • Lxml » Lxml » Version: 4.2.3
    cpe:2.3:a:lxml:lxml:4.2.3
  • Lxml » Lxml » Version: 4.2.4
    cpe:2.3:a:lxml:lxml:4.2.4
  • Lxml » Lxml » Version: 4.2.5
    cpe:2.3:a:lxml:lxml:4.2.5
  • Lxml » Lxml » Version: 4.2.6
    cpe:2.3:a:lxml:lxml:4.2.6
  • Lxml » Lxml » Version: 4.3.0
    cpe:2.3:a:lxml:lxml:4.3.0
  • Lxml » Lxml » Version: 4.6.2
    cpe:2.3:a:lxml:lxml:4.6.2
  • Netapp » Solidfire » Version: N/A
    cpe:2.3:a:netapp:solidfire:-
  • Netapp » Solidfire Enterprise Sds » Version: N/A
    cpe:2.3:a:netapp:solidfire_enterprise_sds:-
  • cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3
  • cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1
  • cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0
  • Oracle » Http Server » Version: 12.2.1.3.0
    cpe:2.3:a:oracle:http_server:12.2.1.3.0
  • Oracle » Http Server » Version: 12.2.1.4.0
    cpe:2.3:a:oracle:http_server:12.2.1.4.0
  • Oracle » Zfs Storage Appliance Kit » Version: 8.8
    cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8
  • Netapp » Hci Storage Node » Version: N/A
    cpe:2.3:h:netapp:hci_storage_node:-
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0
  • Fedoraproject » Fedora » Version: 34
    cpe:2.3:o:fedoraproject:fedora:34
  • Fedoraproject » Fedora » Version: 35
    cpe:2.3:o:fedoraproject:fedora:35
  • Netapp » Hci Storage Node Firmware » Version: N/A
    cpe:2.3:o:netapp:hci_storage_node_firmware:-


Contact Us

Shodan ® - All rights reserved