This repository was archived by the owner on Oct 25, 2023. It is now read-only.
Releases: Skyscanner/whispers
Releases · Skyscanner/whispers
1.4.3
1.4.2
1.4.1
1.4.0
1.3.12
1.3.11
1.3.10
1.3.9
CVE-2020-27783
moderate severity
Vulnerable versions: < 4.6.2
Patched version: 4.6.2
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could exploit this flaw to run arbitrary HTML/JS code.