RHSA-2021:1898: Moderate: python-lxml security update
lxml is an XML processing library providing access to libxml2 and libxslt libraries using the Python ElementTree API. Security Fix(es): python-lxml: mXSS due to the use of improper parser (CVE-2020-27783) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:1898?
The severity of RHSA-2021:1898 is classified as moderate.
How do I fix RHSA-2021:1898?
To fix RHSA-2021:1898, upgrade to python-lxml version 4.2.3-2.el8 or later.
What vulnerability does RHSA-2021:1898 address?
RHSA-2021:1898 addresses a mXSS vulnerability due to the use of an improper parser, identified as CVE-2020-27783.
Which packages are affected by RHSA-2021:1898?
Affected packages include python-lxml, python3-lxml, and their respective debug sources in versions less than 4.2.3-2.el8.
Is there a specific version that resolves RHSA-2021:1898?
Yes, upgrading to python-lxml version 4.2.3-2.el8 or higher resolves RHSA-2021:1898.