RHSA-2022:1932: Moderate: python-lxml security update
lxml is an XML processing library providing access to libxml2 and libxslt libraries using the Python ElementTree API. Security Fix(es): python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1932?
The severity of RHSA-2022:1932 is considered to be important.
How do I fix RHSA-2022:1932?
To fix RHSA-2022:1932, update the affected packages to version 4.2.3-4.el8 or later.
What vulnerability is addressed in RHSA-2022:1932?
RHSA-2022:1932 addresses the vulnerability CVE-2021-43818 in the python-lxml package.
Which packages are affected by RHSA-2022:1932?
The affected packages include python-lxml, python3-lxml, and their corresponding debugsource and debuginfo packages.
Is there a workaround for RHSA-2022:1932?
There is no official workaround for RHSA-2022:1932; updating the affected packages is the recommended course of action.