CVE-2020-29128
Summary
| CVE | CVE-2020-29128 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-26 05:15:00 UTC |
| Updated | 2020-12-03 16:48:00 UTC |
| Description | petl before 1.68, in some configurations, allows resolution of entities in an XML document. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2020-29128: XXE in petl < 1.68 · Advisory · petl-developers/petl · GitHub |
MISC |
github.com |
Third Party Advisory |
| Added new parameter parser in fromxml() for custom parsers by juarezr · Pull Request #527 · petl-developers/petl · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Security issue · Issue #526 · petl-developers/petl · GitHub |
MISC |
github.com |
Issue Tracking, Third Party Advisory |
| Added new parameter parser in fromxml() for custom parsers by juarezr · Pull Request #527 · petl-developers/petl · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| advisories/cve-2020-29128.md at master · nvn1729/advisories · GitHub |
MISC |
github.com |
Third Party Advisory |
| Comparing v1.6.7...v1.6.8 · petl-developers/petl · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Changes — petl 1.6.8 documentation |
MISC |
petl.readthedocs.io |
Release Notes, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982725 Python (pip) Security Update for petl (GHSA-69q2-p9xp-739v)