CVE-2022-48565
Summary
| CVE | CVE-2022-48565 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2023-11-07 03:56:00 UTC |
| Description | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 38 Update: python2.7-2.7.18-35.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python2.7-2.7.18-35.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python2.7-2.7.18-35.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python2.7-2.7.18-35.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 3614-1] python3.7 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 39 Update: python2.7-2.7.18-35.fc39 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 3575-1] python2.7 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 39 Update: python2.7-2.7.18-35.fc39 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Issue 42051: [security] Avoid plistlib XML vulnerabilities by rejecting entity directives - Python tracker | MISC | bugs.python.org | |
| CVE-2022-48565 Python Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284647 Fedora Security Update for python2.7 (FEDORA-2023-e47078af3e)
- 284648 Fedora Security Update for python2.7 (FEDORA-2023-348a0dbcf3)
- 285201 Fedora Security Update for python2.7 (FEDORA-2023-ea38857cc3)
- 356421 Amazon Linux Security Advisory for python3 : ALAS2-2023-2317
- 356554 Amazon Linux Security Advisory for python27 : ALAS-2023-1880
- 356576 Amazon Linux Security Advisory for python : ALAS2-2023-2330
- 378864 Python Extensible Markup Language (XML) External Entity Vulnerability
- 6000148 Debian Security Update for python2.7 (DLA 3575-1)
- 6000279 Debian Security Update for python3.7 (DLA 3614-1)
- 673325 EulerOS Security Update for python2 (EulerOS-SA-2024-1290)
- 673594 EulerOS Security Update for python (EulerOS-SA-2024-1160)
- 673778 EulerOS Security Update for python3 (EulerOS-SA-2024-1291)
- 755046 SUSE Enterprise Linux Security Update for python (SUSE-SU-2023:4001-1)
- 755169 SUSE Enterprise Linux Security Update for python (SUSE-SU-2023:4220-1)