Skip to content

Improper Restriction of XML External Entity Reference in untangle

Moderate
stchris published GHSA-f83q-2cp7-qrjg Jul 26, 2022

Package

pip untangle (pip)

Affected versions

< 1.2.1

Patched versions

1.2.1

Description

Impact

An attacker may be able to read the contents of local files. This affects untangle versions up to and including 1.2.0

Patches

The problem has been fixed with version 1.2.1

Workarounds

None

References

https://jvn.jp/en/jp/JVN30454777/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2022-31471

Weaknesses