CVE-2021-23418
Summary
| CVE | CVE-2021-23418 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-29 18:15:00 UTC |
| Updated | 2021-08-05 18:58:00 UTC |
| Description | The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| XML External Entity (XXE) Injection in glances | Snyk |
CONFIRM |
snyk.io |
|
| Security audit - B411 · Issue #1025 · nicolargo/glances · GitHub |
CONFIRM |
github.com |
|
| Security audit - B411 #1025 · nicolargo/glances@9d6051b · GitHub |
CONFIRM |
github.com |
|
| Add NEWS file and improve Makefile · nicolargo/glances@4b87e97 · GitHub |
CONFIRM |
github.com |
|
| Security audit - B411 #1025 · nicolargo/glances@85d5a6b · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Unknown
Legacy QID Mappings
- 184998 Debian Security Update for glances (CVE-2021-23418)
- 981354 Python (pip) Security Update for Glances (GHSA-r2mj-8wgq-73m6)