Опубликовано: 02 сент. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
XML External Entity Injection in PyWPS
An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-39371
- https://github.com/geopython/OWSLib/issues/790
- https://github.com/geopython/pywps/pull/616
- https://github.com/geopython/pywps/commit/7d6b26a2e931df2feca0b7fb24f4d01610825aee
- https://github.com/advisories/GHSA-p9wf-3xpg-c9g5
- https://github.com/pypa/advisory-database/tree/main/vulns/pywps/PYSEC-2021-121.yaml
- https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html
Пакеты
Наименование
pywps
pip
Затронутые версииВерсия исправления
< 4.5.0
4.5.0
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 4 лет назад
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
CVSS3: 7.5
nvd
больше 4 лет назад
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
CVSS3: 7.5
debian
больше 4 лет назад
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an ...