Описание
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 0.13.0-1ubuntu1 |
| esm-apps-legacy/xenial | released | 0.9.2-3ubuntu0.1~esm1 |
| esm-apps/bionic | released | 0.11.0-1ubuntu0.1~esm1 |
| esm-apps/focal | released | 0.12.0-1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 0.12.0-2ubuntu0.1~esm1 |
| esm-apps/xenial | released | 0.9.2-3ubuntu0.1~esm1 |
| jammy | needed | |
| noble | released | 0.13.0-1ubuntu0.24.04.1 |
| plucky | released | 0.13.0-1ubuntu0.25.04.1 |
| questing | released | 0.13.0-1ubuntu1 |
Показывать по
EPSS
Связанные уязвимости
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.
XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 before 0.15.1. NOTE: the scope of this CVE is disputed by the vendor on the grounds that xmltodict.unparse() delegates element-name handling to Python's xml.sax.saxutils.XMLGenerator, and that XMLGenerator should be the component performing validation.
XML Injection vulnerability in xmltodict allows Input Data Manipulatio ...
EPSS