Skip to content

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in untangle

Moderate
stchris published GHSA-7xr3-6ggc-wc9p Jul 26, 2022

Package

pip untangle (pip)

Affected versions

< 1.2.1

Patched versions

1.2.1

Description

Impact

An attacker may be able to cause a denial-of-service (DoS) condition on the server on which the product is running. This affects untangle versions up to and including 1.2.0

Patches

The problem has been fixed with version 1.2.1

Workarounds

None

References

https://jvn.jp/en/jp/JVN30454777/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-33977

Weaknesses