Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-836c-xg97-8p4h

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

libtaxii Server-Side Request Forgery vulnerability

"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.""

Пакеты

Наименование

libtaxii

pip
Затронутые версииВерсия исправления

< 1.1.118

1.1.118

EPSS

Процентиль: 64%
0.0046
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.

EPSS

Процентиль: 64%
0.0046
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-918