{"api_version":"1","generated_at":"2026-07-23T16:45:51+00:00","cve":"CVE-2021-23418","urls":{"html":"https://cve.report/CVE-2021-23418","api":"https://cve.report/api/cve/CVE-2021-23418.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23418","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23418"},"summary":{"title":"CVE-2021-23418","description":"The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2021-07-29 18:15:00","updated_at":"2021-08-05 18:58:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807","name":"N/A","refsource":"CONFIRM","tags":[],"title":"XML External Entity (XXE) Injection in glances | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/nicolargo/glances/issues/1025","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Security audit - B411 · Issue #1025 · nicolargo/glances · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Security audit - B411 #1025 · nicolargo/glances@9d6051b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Add NEWS file and improve Makefile · nicolargo/glances@4b87e97 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Security audit - B411 #1025 · nicolargo/glances@85d5a6b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23418","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23418","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Unknown","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"23418","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"glances_project","cpe5":"glances","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-23418","qid":"184998","title":"Debian Security Update for glances (CVE-2021-23418)"},{"cve":"CVE-2021-23418","qid":"981354","title":"Python (pip) Security Update for Glances (GHSA-r2mj-8wgq-73m6)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2021-07-29T17:45:15.560277Z","ID":"CVE-2021-23418","STATE":"PUBLIC","TITLE":"XML External Entity (XXE) Injection"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Glances","version":{"version_data":[{"version_affected":"<","version_value":"3.2.1"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"XML External Entity (XXE) Injection"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807","name":"https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807"},{"refsource":"MISC","url":"https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94","name":"https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94"},{"refsource":"MISC","url":"https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a","name":"https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a"},{"refsource":"MISC","url":"https://github.com/nicolargo/glances/issues/1025","name":"https://github.com/nicolargo/glances/issues/1025"},{"refsource":"MISC","url":"https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32","name":"https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32"}]},"description":{"description_data":[{"lang":"eng","value":"The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks."}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},"credit":[{"lang":"eng","value":"Unknown"}]},"nvd":{"publishedDate":"2021-07-29 18:15:00","lastModifiedDate":"2021-08-05 18:58:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:glances_project:glances:*:*:*:*:*:*:*:*","versionEndExcluding":"3.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23418","Ordinal":"198145","Title":"CVE-2021-23418","CVE":"CVE-2021-23418","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23418","Ordinal":"1","NoteData":"The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"23418","Ordinal":"2","NoteData":"2021-07-29","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"23418","Ordinal":"3","NoteData":"2021-07-29","Type":"Other","Title":"Modified"}]}}}