CVE-2014-3146
Published May 14, 2014
Last updated 7 years ago
Overview
- Description
- Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- Per: http://cwe.mitre.org/data/definitions/184.html "CWE-184: Incomplete Blacklist"
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:lxml:lxml:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAAC1D54-E4B7-4212-A281-9AE313C7A9DC", "versionEndIncluding": "3.3.4" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "299444A8-4017-4358-9B35-0A9C475E5FB2" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C48BCC21-D20B-4390-870D-C88C9863D46B" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "779553CC-B269-479D-8885-1251541AC8B3" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F73BEB9C-4F4F-4F63-81FF-0B65D6068DA4" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39876055-AAFD-4584-872E-044C111417B1" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25FD79CE-8C7C-4994-80D6-CA1E98C062EC" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C641DEEC-643D-48AA-A2BC-3066CD02D072" }, { "criteria": "cpe:2.3:a:lxml:lxml:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C29C1834-7ADB-4444-B892-083CCA6FD0EA" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08F26EDB-5E1C-453A-8332-6DF4FD0627F2" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24F0DD2C-2836-4477-849A-F154C0BF37D6" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FD4F21D-D09A-488A-A457-2BB5589B6B31" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9DFE602-6616-4369-9CA7-5C35FA80A4B1" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB0F6513-1D7F-48D8-820C-F78A7935BE8A" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6F36E5C1-7DF3-4692-8FEE-F1007E57399B" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4551FDBD-8975-4399-BD00-02EC03AD0CC5" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F067084A-72E9-4D45-8EB9-534F718FD11C" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54021062-86DC-4B28-AD87-963F0C415798" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B01E478-3B3A-4B05-AEDC-6A404DB7803A" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20751814-185B-489F-AD35-239EA168D293" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB0286DD-FDA3-4B31-B579-6FD68BF88B87" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B56F992-FEE5-4EB0-BB5D-B55BC2A5CDCB" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFEEE806-93A1-4683-9524-66B969E96D9C" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21DC60E8-18F6-414F-81A0-37EAEF9D73A9" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B693FE5-0F4F-441C-8D6D-B2B0C00F4784" }, { "criteria": "cpe:2.3:a:lxml:lxml:1.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3319AB13-F589-44CA-8936-3A4D23C3C8E7" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCC3B496-51EE-41E0-B785-E9E4FA530116" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "041CED1D-1D91-4BAC-8182-BE5870ADFEB7" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F93A757-1B1A-4E69-89FD-B738F80C560D" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E58E8C6-6979-4256-947C-887D7E3F611A" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06AC5F6D-F72C-4D30-997D-0202D9CACA49" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C2AFA1D4-265D-4B72-B6A0-9F31F4612C33" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A216360-8892-4118-96DE-77EB7D17CA51" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A3513EB-8A8F-43AE-B079-AA5E27569CDB" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4EDD3E4E-A3C0-4686-BD91-9B58CBC74DAB" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDDCFAEE-9C4B-4610-81A5-A5AD4420D579" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88206B3E-503D-4C9C-85A2-8E1FB720E962" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA9D682D-CF6B-43FB-A29D-50BC54FB3E99" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "925AF6FD-EB7C-48EA-8747-5066103C58A8" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "940C521B-EF4D-4A90-B1E1-E52C9793D645" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3AB9E27-9017-4207-A66E-199CFD9EE4B8" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8900D734-E782-4759-A4DD-D577A462042C" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C66C8E1-EE4E-4462-8844-15995FD1FB93" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9747A1D-D644-442B-B2AE-C8D962B187E4" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "777CB9D2-EACF-4F1A-B533-BFED0B27D214" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58001941-9E40-45D7-9892-C79B7A8F3720" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C7FE4FA-6C7C-4A3C-B2EE-C6B70C8A3F48" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7E1DFA9-CC7B-4E9F-A2E4-0FE8DF536101" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B40A7ED8-0D71-430E-BCF1-640D816C0230" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8790354C-5A4B-4CD3-ACB1-FE5AA0900281" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1B6857F-0990-4083-9876-5DDF5FA473B0" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "049C39E8-4804-4048-9999-A1EAFD5B910B" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C51525BB-5967-4C7F-9188-5E3895B3A2CB" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9DC336F-02E7-4E1C-A8EA-21DEE84A52F2" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD4FB16F-6BFA-4D2A-8D48-1A01154C3F85" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00400181-FA11-49CE-B932-4F21A8278D81" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6392F721-9F0D-4BBC-B392-A9C6F14F7F17" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95F6166A-3856-451D-AFAA-56C5D09752D1" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE0D09BB-8796-40F1-8599-107B9C775C12" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7550F3D6-4FCC-4AD5-A92D-D984A6824AB4" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30EAB48D-A728-46FB-92B3-0B97CF85E72B" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "127C133B-5022-46FB-9D6F-05FB2E83CA87" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3E49A50-3861-4265-BB2B-ABEA50C6DE7E" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D72B1891-2E24-4DA7-B243-80306866F934" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDB6BCDC-7207-4895-8746-E40DDD1D5585" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F0D4EB6-5ED8-4018-A1FE-9BEB6D511830" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "627C0FA1-7425-4E6B-92C5-652D4F62ECAD" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70059F02-B63D-4583-8AD4-769BA648317F" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC4FCBFB-632A-451E-8A17-C4A8F8A65AAF" }, { "criteria": "cpe:2.3:a:lxml:lxml:2.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8763BB95-EBF9-40A1-908C-4207D87FE578" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC015741-8F99-4F3D-B3F6-07BF23A70DC0" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D1A35DEE-2561-4B4A-BFE0-C443C70175BA" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FBFD00B-5821-400E-A83C-FB0D1C26A4DE" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AB7BA95-5BEC-4AC6-8F93-5D918D1B31D0" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDAEFE73-F873-4F48-A274-F6CCB40766DA" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1ED8D046-5701-4AD4-BFA6-D186AA596B26" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.1:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "685D86D0-4A37-4B9B-BD70-C1127EA51907" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B72ABBA-9319-4BFE-8F3B-F6F36F64EB12" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2684097-3082-4612-8E1B-5CA6D2E20E3E" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7981486F-129D-433B-A489-0AB90A2062E5" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45C3BB16-3D44-43E8-AEF5-3454495F0CC0" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD521388-6E28-427E-9086-79BCEDB1025F" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BFA21DA-4807-496D-B63A-F95E6E9F39FF" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87B742D1-4838-4D48-A17A-386E0CF517B1" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1191E15-DC8D-4D2B-8563-10DFFF60CD51" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BA34CA6-7309-490C-8DB7-7F051F9C3CDE" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E58C7CFD-0135-4D59-8D9D-A12A7BACF387" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5FE30C26-028B-41A1-842C-1AF19E551F54" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "188EA215-8ACA-482F-9283-6780E29B5F4E" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "738B75AC-0AFC-4108-88A1-80EC6D03FBD6" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99226ADA-A62E-4366-BDD1-1D33BDCA813F" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F1E30E8-484C-4925-9B6F-DD266AC602B7" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02E0191B-661F-4C60-AC7F-68B95E730013" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7922BC86-D318-404B-A39B-8AC9B1AF70BF" }, { "criteria": "cpe:2.3:a:lxml:lxml:3.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26BFDC2C-CAFE-4301-903F-31713885EB94" } ], "operator": "OR" } ] } ]