The vendor explicitly identifies these products as affected by this CVE.
- python-unversioned-command as a component of Red Hat Enterprise Linux 10
- python3 as a component of Red Hat Enterprise Linux 10
- python3-debug as a component of Red Hat Enterprise Linux 10
- python3-devel as a component of Red Hat Enterprise Linux 10
- python3-idle as a component of Red Hat Enterprise Linux 10
- python3-libs as a component of Red Hat Enterprise Linux 10
- python3-test as a component of Red Hat Enterprise Linux 10
- python3-tkinter as a component of Red Hat Enterprise Linux 10
- python3.12.src as a component of Red Hat Enterprise Linux 10
- python as a component of Red Hat Enterprise Linux 6
- python-devel as a component of Red Hat Enterprise Linux 6
- python-libs as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the ` ` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
