QID 980237
QID 980237: Python (pip) Security Update for easy-xml (GHSA-v899-28g4-qmh8)
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v899-28g4-qmh8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-v899-28g4-qmh8 -
github.com/advisories/GHSA-v899-28g4-qmh8
CVEs related to QID 980237
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v899-28g4-qmh8 | easy-xml |
|