vuln-list-alt/oval/c10f1/ALT-PU-2021-1429/definitions.json
2024-06-28 13:17:52 +00:00

105 lines
3.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20211429",
"Version": "oval:org.altlinux.errata:def:20211429",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-1429: package `python3-module-lxml` update to version 4.6.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-1429",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-1429",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-03620",
"RefURL": "https://bdu.fstec.ru/vul/2021-03620",
"Source": "BDU"
},
{
"RefID": "CVE-2020-27783",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-27783",
"Source": "CVE"
}
],
"Description": "This update upgrades python3-module-lxml to version 4.6.2-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03620: Уязвимость модуля clean библиотеки для обработки разметки XML и HTML Lxml, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность защищаемой информации\n\n * CVE-2020-27783: A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-03-02"
},
"Updated": {
"Date": "2021-03-02"
},
"BDUs": [
{
"ID": "BDU:2021-03620",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2021-03620",
"Impact": "Low",
"Public": "20201203"
}
],
"CVEs": [
{
"ID": "CVE-2020-27783",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-27783",
"Impact": "Low",
"Public": "20201203"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20211429001",
"Comment": "python3-module-lxml is earlier than 0:4.6.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20211429002",
"Comment": "python3-module-lxml-doc is earlier than 0:4.6.2-alt1"
}
]
}
]
}
}
]
}