An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3575-1 | python2.7 security update |
Debian DLA |
DLA-3614-1 | python3.7 security update |
EUVD |
EUVD-2022-51261 | An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities. |
Ubuntu USN |
USN-6354-1 | Python vulnerability |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
Ubuntu USN |
USN-7180-1 | Python vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-03T17:41:29.341Z
Reserved: 2023-07-23T00:00:00.000Z
Link: CVE-2022-48565
Updated: 2024-08-03T15:17:54.848Z
Status : Modified
Published: 2023-08-22T19:16:32.007
Modified: 2024-11-21T07:33:30.950
Link: CVE-2022-48565
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN