Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gh8-gr6x-7q26

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

SOAPpy vulnerable to XXE attacks

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

Пакеты

Наименование

SOAPpy

pip
Затронутые версииВерсия исправления

<= 0.12.5

0.12.6

EPSS

Процентиль: 73%
0.00755
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

redhat
почти 12 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

nvd
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

debian
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansi ...

EPSS

Процентиль: 73%
0.00755
Низкий

Дефекты

CWE-119