Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-9375

Опубликовано: 01 сент. 2025
Источник: debian
EPSS Низкий

Описание

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-xmltodictfixed1.0.3-1experimentalpackage
python-xmltodictfixed0.13.0-1.1package
python-xmltodictfixed0.13.0-1.1~deb13u1trixiepackage
python-xmltodictfixed0.13.0-1.1~deb12u1bookwormpackage
python-xmltodictpostponedbullseyepackage

Примечания

  • https://github.com/martinblech/xmltodict/issues/377

  • https://fluidattacks.com/advisories/mono

  • https://github.com/martinblech/xmltodict/commit/ecd456ab88d379514b116ef9293318b74e5ed3ee (v0.15.0)

  • https://github.com/martinblech/xmltodict/commit/f98c90f071228ed73df997807298e1df4f790c33 (v0.15.1)

EPSS

Процентиль: 37%
0.00447
Низкий

Связанные уязвимости

ubuntu
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

CVSS3: 5.3
redhat
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

nvd
12 месяцев назад

XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.

suse-cvrf
10 месяцев назад

Security update for python-xmltodict

suse-cvrf
10 месяцев назад

Security update for python-xmltodict

EPSS

Процентиль: 37%
0.00447
Низкий