9.8

CVE-2020-29128

petl before 1.68, in some configurations, allows resolution of entities in an XML document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Petl ProjectPetl Version < 1.6.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.28% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-91 XML Injection (aka Blind XPath Injection)

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

https://github.com/nvn1729/advisories/blob/master/cve-2020-29128.md
Third Party Advisory
https://github.com/petl-developers/petl/compare/v1.6.7...v1.6.8
Patch
Third Party Advisory
https://github.com/petl-developers/petl/issues/526
Third Party Advisory
Issue Tracking
https://github.com/petl-developers/petl/pull/527
Patch
Third Party Advisory
https://github.com/petl-developers/petl/pull/527/commits/1b0a09f08c3cdfe2e69647bd02f97c1367a5b5f8
Patch
Third Party Advisory
https://github.com/petl-developers/petl/security/advisories/GHSA-f5gc-p5m3-v347
Third Party Advisory
https://petl.readthedocs.io/en/stable/changes.html
Vendor Advisory
Release Notes