OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution, and could lead to arbitrary file reads from an attacker-controlled XML payload. This affects all XML parsing in the codebase. This issue has been addressed in version 0.28.1. All users are advised to upgrade. The only known workaround is to patch the library manually. See `GHSA-8h9c-r582-mggc` for details.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3470-1 | owslib security update |
Debian DSA |
DSA-5426-1 | owslib security update |
EUVD |
EUVD-2023-0189 | OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution, and could lead to arbitrary file reads from an attacker-controlled XML payload. This affects all XML parsing in the codebase. This issue has been addressed in version 0.28.1. All users are advised to upgrade. The only known workaround is to patch the library manually. See `GHSA-8h9c-r582-mggc` for details. |
Github GHSA |
GHSA-8h9c-r582-mggc | OWSLib vulnerable to XML External Entity (XXE) Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T15:00:10.207Z
Reserved: 2023-03-01T19:03:56.632Z
Link: CVE-2023-27476
Updated: 2024-08-02T12:09:43.480Z
Status : Modified
Published: 2023-03-08T00:15:08.997
Modified: 2024-11-21T07:52:58.840
Link: CVE-2023-27476
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA