VDB
Sign up
—

PYSEC-2017-15

Quick fix

PYSEC-2017-15 — html5lib: upgrade to the fixed version with the command below.

pip install --upgrade 'html5lib>=9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7'

Details

The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different vulnerability than CVE-2016-9909.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/html5lib
Introduced in: 0Fixed in: 9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7
Fixpip install --upgrade 'html5lib>=9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7'

References