Описание
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
Ссылки
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Mailing ListThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:python:openpyxl:2.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00528
Низкий
8.2 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 8.2
ubuntu
почти 9 лет назад
Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
CVSS3: 8.2
debian
почти 9 лет назад
Openpyxl 2.4.1 resolves external entities by default, which allows rem ...
CVSS3: 8.2
github
больше 3 лет назад
Improper Restriction of XML External Entity Reference in Openpyxl
EPSS
Процентиль: 67%
0.00528
Низкий
8.2 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-611