Improper Restriction of XML External Entity Reference in ladon
Critical severity
GitHub Reviewed
Published
Jul 26, 2019
to the GitHub Advisory Database
•
Updated Sep 27, 2024
Description
Published by the National Vulnerability Database
Jul 18, 2019
Reviewed
Jul 25, 2019
Published to the GitHub Advisory Database
Jul 26, 2019
Last updated
Sep 27, 2024
Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance: https://bitbucket.org/jakobsg/ladon/src/42944fc012a3a48214791c120ee5619434505067/src/ladon/interfaces/soap.py#lines-688. The attack vector is: Send a specially crafted SOAP call.
References