The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2021-07-29T17:50:12.851255Z
Updated: 2024-09-16T17:38:39.943Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23418
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-29T18:15:07.727
Modified: 2024-11-21T05:51:43.380
Link: CVE-2021-23418
Redhat
No data.