-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat Software Collections security update
Advisory ID:       RHSA-2022:1664-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:1664
Issue date:        2022-05-02
CVE Names:         CVE-2021-43818 
====================================================================
1. Summary:

An update for rh-python38-python, rh-python38-python-lxml, and
rh-python38-python-pip is now available for Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

3. Description:

lxml is an XML processing library providing access to libxml2 and libxslt
libraries using the Python ElementTree API.

Security Fix(es):

* python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass
through (CVE-2021-43818)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2032569 - CVE-2021-43818 python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through
2064443 - SCL Python 3.8: pip contains bundled pre-built exe files in site-packages/pip/_vendor/distlib/ [rhscl-3.8.z]
2068592 - Rebase the python3.8 interpreter to version 3.8.13 [rhscl-3.8.z]

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-python38-python-3.8.13-1.el7.src.rpm
rh-python38-python-lxml-4.4.1-8.el7.src.rpm
rh-python38-python-pip-19.3.1-3.el7.src.rpm

noarch:
rh-python38-python-pip-19.3.1-3.el7.noarch.rpm
rh-python38-python-pip-wheel-19.3.1-3.el7.noarch.rpm
rh-python38-python-rpm-macros-3.8.13-1.el7.noarch.rpm
rh-python38-python-srpm-macros-3.8.13-1.el7.noarch.rpm

ppc64le:
rh-python38-python-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-debug-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-debuginfo-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-devel-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-idle-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-libs-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-lxml-4.4.1-8.el7.ppc64le.rpm
rh-python38-python-lxml-debuginfo-4.4.1-8.el7.ppc64le.rpm
rh-python38-python-test-3.8.13-1.el7.ppc64le.rpm
rh-python38-python-tkinter-3.8.13-1.el7.ppc64le.rpm

s390x:
rh-python38-python-3.8.13-1.el7.s390x.rpm
rh-python38-python-debug-3.8.13-1.el7.s390x.rpm
rh-python38-python-debuginfo-3.8.13-1.el7.s390x.rpm
rh-python38-python-devel-3.8.13-1.el7.s390x.rpm
rh-python38-python-idle-3.8.13-1.el7.s390x.rpm
rh-python38-python-libs-3.8.13-1.el7.s390x.rpm
rh-python38-python-lxml-4.4.1-8.el7.s390x.rpm
rh-python38-python-lxml-debuginfo-4.4.1-8.el7.s390x.rpm
rh-python38-python-test-3.8.13-1.el7.s390x.rpm
rh-python38-python-tkinter-3.8.13-1.el7.s390x.rpm

x86_64:
rh-python38-python-3.8.13-1.el7.x86_64.rpm
rh-python38-python-debug-3.8.13-1.el7.x86_64.rpm
rh-python38-python-debuginfo-3.8.13-1.el7.x86_64.rpm
rh-python38-python-devel-3.8.13-1.el7.x86_64.rpm
rh-python38-python-idle-3.8.13-1.el7.x86_64.rpm
rh-python38-python-libs-3.8.13-1.el7.x86_64.rpm
rh-python38-python-lxml-4.4.1-8.el7.x86_64.rpm
rh-python38-python-lxml-debuginfo-4.4.1-8.el7.x86_64.rpm
rh-python38-python-test-3.8.13-1.el7.x86_64.rpm
rh-python38-python-tkinter-3.8.13-1.el7.x86_64.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-python38-python-3.8.13-1.el7.src.rpm
rh-python38-python-lxml-4.4.1-8.el7.src.rpm
rh-python38-python-pip-19.3.1-3.el7.src.rpm

noarch:
rh-python38-python-pip-19.3.1-3.el7.noarch.rpm
rh-python38-python-pip-wheel-19.3.1-3.el7.noarch.rpm
rh-python38-python-rpm-macros-3.8.13-1.el7.noarch.rpm
rh-python38-python-srpm-macros-3.8.13-1.el7.noarch.rpm

x86_64:
rh-python38-python-3.8.13-1.el7.x86_64.rpm
rh-python38-python-debug-3.8.13-1.el7.x86_64.rpm
rh-python38-python-debuginfo-3.8.13-1.el7.x86_64.rpm
rh-python38-python-devel-3.8.13-1.el7.x86_64.rpm
rh-python38-python-idle-3.8.13-1.el7.x86_64.rpm
rh-python38-python-libs-3.8.13-1.el7.x86_64.rpm
rh-python38-python-lxml-4.4.1-8.el7.x86_64.rpm
rh-python38-python-lxml-debuginfo-4.4.1-8.el7.x86_64.rpm
rh-python38-python-test-3.8.13-1.el7.x86_64.rpm
rh-python38-python-tkinter-3.8.13-1.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2021-43818
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYm+vntzjgjWX9erEAQi/gg/8CuTnUa8Ds0aFv3nwfjfiZcq3N8VWxTHB
kdG/iamBiMPAjPMRPFB7HqetmzbmbzB3Qc/1QYbRvnkYGGUoDzdhxlwjhb9lkgwU
rfWtpB4A4ryffT+V2va/8GDBnipLGmT9Myg0CcJmQ+gi75zB/+nGgAGCoxpJGCv7
QDLm+IIKVUpGmDQkny2BSWzA64iQJMz2Kb1gy/igOLHyn4RmJkrt8nqZbLoN1KF7
KnQG6GxMtfai3PmoHBQUA/CsD49V3Z2kYgT6xmq9l3xzYLkIeMSRvEqPdkwGOROP
9l+SV7VvD/lqKTgpfAyAw7BzG5T088ZgMB1MjIHDbU8I0uy2A5PvGjfdW1u35okT
CZnpzTPWLeJqDO4rs4YdU8uJRJjm9gA20Ts9I0S1GIT/oJIW3FxElVr1ya2bQQNc
OR1ytZvJBfR7QzjkzLIzLUEoyLgRd/gvja59+SYLM3RMxjfcY8OPZk6MbBXvdkwL
kY3E2k/W4jCXMXI9bb7okNO/RmGrGQ3Zz526NlOsOJZwtJrqyFILPL1V/bDOFGDW
lL1oQnROilEIZY07RpYDw6j042Tp3I0imv3TX6o192dYYJP1ybDNv9jPmcl77Eqt
p2r8rtnA0NO8yUwEBUFkoOyI4MBmLmqy7tJCI2r51KvMgyTaaAo087kNnwIbvWG3
lanRNEaBolA=vlmi
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-1664:01 Moderate: Red Hat Software Collections security

An update for rh-python38-python, rh-python38-python-lxml, and rh-python38-python-pip is now available for Red Hat Software Collections

Summary

lxml is an XML processing library providing access to libxml2 and libxslt libraries using the Python ElementTree API.
Security Fix(es):
* python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2021-43818 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-python38-python-3.8.13-1.el7.src.rpm rh-python38-python-lxml-4.4.1-8.el7.src.rpm rh-python38-python-pip-19.3.1-3.el7.src.rpm
noarch: rh-python38-python-pip-19.3.1-3.el7.noarch.rpm rh-python38-python-pip-wheel-19.3.1-3.el7.noarch.rpm rh-python38-python-rpm-macros-3.8.13-1.el7.noarch.rpm rh-python38-python-srpm-macros-3.8.13-1.el7.noarch.rpm
ppc64le: rh-python38-python-3.8.13-1.el7.ppc64le.rpm rh-python38-python-debug-3.8.13-1.el7.ppc64le.rpm rh-python38-python-debuginfo-3.8.13-1.el7.ppc64le.rpm rh-python38-python-devel-3.8.13-1.el7.ppc64le.rpm rh-python38-python-idle-3.8.13-1.el7.ppc64le.rpm rh-python38-python-libs-3.8.13-1.el7.ppc64le.rpm rh-python38-python-lxml-4.4.1-8.el7.ppc64le.rpm rh-python38-python-lxml-debuginfo-4.4.1-8.el7.ppc64le.rpm rh-python38-python-test-3.8.13-1.el7.ppc64le.rpm rh-python38-python-tkinter-3.8.13-1.el7.ppc64le.rpm
s390x: rh-python38-python-3.8.13-1.el7.s390x.rpm rh-python38-python-debug-3.8.13-1.el7.s390x.rpm rh-python38-python-debuginfo-3.8.13-1.el7.s390x.rpm rh-python38-python-devel-3.8.13-1.el7.s390x.rpm rh-python38-python-idle-3.8.13-1.el7.s390x.rpm rh-python38-python-libs-3.8.13-1.el7.s390x.rpm rh-python38-python-lxml-4.4.1-8.el7.s390x.rpm rh-python38-python-lxml-debuginfo-4.4.1-8.el7.s390x.rpm rh-python38-python-test-3.8.13-1.el7.s390x.rpm rh-python38-python-tkinter-3.8.13-1.el7.s390x.rpm
x86_64: rh-python38-python-3.8.13-1.el7.x86_64.rpm rh-python38-python-debug-3.8.13-1.el7.x86_64.rpm rh-python38-python-debuginfo-3.8.13-1.el7.x86_64.rpm rh-python38-python-devel-3.8.13-1.el7.x86_64.rpm rh-python38-python-idle-3.8.13-1.el7.x86_64.rpm rh-python38-python-libs-3.8.13-1.el7.x86_64.rpm rh-python38-python-lxml-4.4.1-8.el7.x86_64.rpm rh-python38-python-lxml-debuginfo-4.4.1-8.el7.x86_64.rpm rh-python38-python-test-3.8.13-1.el7.x86_64.rpm rh-python38-python-tkinter-3.8.13-1.el7.x86_64.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-python38-python-3.8.13-1.el7.src.rpm rh-python38-python-lxml-4.4.1-8.el7.src.rpm rh-python38-python-pip-19.3.1-3.el7.src.rpm
noarch: rh-python38-python-pip-19.3.1-3.el7.noarch.rpm rh-python38-python-pip-wheel-19.3.1-3.el7.noarch.rpm rh-python38-python-rpm-macros-3.8.13-1.el7.noarch.rpm rh-python38-python-srpm-macros-3.8.13-1.el7.noarch.rpm
x86_64: rh-python38-python-3.8.13-1.el7.x86_64.rpm rh-python38-python-debug-3.8.13-1.el7.x86_64.rpm rh-python38-python-debuginfo-3.8.13-1.el7.x86_64.rpm rh-python38-python-devel-3.8.13-1.el7.x86_64.rpm rh-python38-python-idle-3.8.13-1.el7.x86_64.rpm rh-python38-python-libs-3.8.13-1.el7.x86_64.rpm rh-python38-python-lxml-4.4.1-8.el7.x86_64.rpm rh-python38-python-lxml-debuginfo-4.4.1-8.el7.x86_64.rpm rh-python38-python-test-3.8.13-1.el7.x86_64.rpm rh-python38-python-tkinter-3.8.13-1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2022:1664-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2022:1664
Issued Date: : 2022-05-02
CVE Names: CVE-2021-43818

Topic

An update for rh-python38-python, rh-python38-python-lxml, andrh-python38-python-pip is now available for Red Hat Software Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64


Bugs Fixed

2032569 - CVE-2021-43818 python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through

2064443 - SCL Python 3.8: pip contains bundled pre-built exe files in site-packages/pip/_vendor/distlib/ [rhscl-3.8.z]

2068592 - Rebase the python3.8 interpreter to version 3.8.13 [rhscl-3.8.z]