GHSA-69q2-p9xp-739v – petl
Package
Manager: pip
Name: petl
Vulnerable Version: <0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Duplicate Advisory: XML Injection in petl ## Duplicate Advisory This advisoerey has been withdrawn because it is a duplicate of GHSA-f5gc-p5m3-v347. This link is maintained to preserve external references. ## Original Description petl before 1.68, in some configurations, allows resolution of entities in an XML document.
Metadata
Created: 2021-04-20T16:32:08Z
Modified: 2024-10-09T20:47:36Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-69q2-p9xp-739v/GHSA-69q2-p9xp-739v.json
CWE IDs: ["CWE-91"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0