Description
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0350 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files. |
Github GHSA |
GHSA-f83q-2cp7-qrjg | untangle vulnerable to Improper Restriction of XML External Entity Reference |
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-03T07:19:06.083Z
Reserved: 2022-07-12T00:00:00.000Z
Link: CVE-2022-31471
No data.
Status : Modified
Published: 2022-07-26T06:15:08.817
Modified: 2024-11-21T07:04:31.290
Link: CVE-2022-31471
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA