Описание
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra/bionic | not-affected | |
| esm-infra/focal | not-affected | |
| esm-infra/xenial | not-affected | |
| focal | not-affected | |
| jammy | not-affected | |
| mantic | not-affected | |
| noble | not-affected | |
| trusty/esm | not-affected |
Показывать по
10
EPSS
Процентиль: 31%
0.00117
Низкий
9.1 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.1
nvd
больше 1 года назад
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
EPSS
Процентиль: 31%
0.00117
Низкий
9.1 Critical
CVSS3