MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
High severity
GitHub Reviewed
Published
Sep 8, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Sep 7, 2022
Published to the GitHub Advisory Database
Sep 8, 2022
Reviewed
Sep 16, 2022
Last updated
Jan 27, 2023
DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.etree' library to parse untrusted XML input.
References