QID 378864
Date Published: 2023-09-25
QID 378864: Python Extensible Markup Language (XML) External Entity Vulnerability
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
Affected version
Python version 3.6 to 3.9.1
QID Detection Logic (Authenticated):
It checks for the vulnerable version from the file py.exe
Successful exploit may lead to XML External Entity (XXE)
Solution
Customers are advised to upgrade to the latest supported python releases to remediate this vulnerability.
For latest release visit here.
For latest release visit here.
Vendor References
- CVE-2022-48565 -
bugs.python.org/issue42051
CVEs related to QID 378864
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-48565 |
|
||
| Python 3.10.0 |
|
||
| Python 3.6.13 |
|
||
| Python 3.7.10 |
|
||
| Python 3.8.7 |
|
||
| Python 3.9.1 |
|