Описание
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| openpyxl | fixed | 2.3.0-3 | package | |
| openpyxl | not-affected | jessie | package | |
| openpyxl | not-affected | wheezy | package |
Примечания
https://www.openwall.com/lists/oss-security/2017/02/07/5
https://bitbucket.org/openpyxl/openpyxl/issues/749
https://bitbucket.org/openpyxl/openpyxl/commits/3b4905f428e1
Связанные уязвимости
CVSS3: 8.2
ubuntu
почти 9 лет назад
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
CVSS3: 8.2
nvd
почти 9 лет назад
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
CVSS3: 8.2
github
больше 3 лет назад
Improper Restriction of XML External Entity Reference in Openpyxl