Description
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0349 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running. |
Github GHSA |
GHSA-7xr3-6ggc-wc9p | untangle vulnerable to XML Entity Expansion |
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-03T08:16:16.078Z
Reserved: 2022-07-12T00:00:00.000Z
Link: CVE-2022-33977
No data.
Status : Modified
Published: 2022-07-26T06:15:08.957
Modified: 2024-11-21T07:08:42.270
Link: CVE-2022-33977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA