Safety vulnerability ID: 26137
The information on this page was manually curated by our Cybersecurity Intelligence Team.
soappy before 0.12.6 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Latest version: 0.12.22
SOAP Services for Python
-------------------
- fix cve CVE Request ---- SOAPpy 0.12.5 Multiple Vulnerabilities -- LOL part
[kiorky]
- fix cve CVE Request ---- SOAPpy 0.12.5 Multiple Vulnerabilities -- XXE part
[kiorky]
- Remove dependency on fpconst.
- adding maptype [Sandro Knauß]
- Support / (and other reserved characters) in the password. [Ionut Turturica]
- Client.HTTPWithTimeout: fixed constructor's docstring and comments -named the diferences
with respect to the overriden method -fixed
wrong reference to class in module 'httplib' -added documentation of param 't[German Larrain
- fixed module docstring location (all imports must be below them)[German Larrain]f
- fix error "Bad types (class java.math.BigInteger -> class java.lang.Integer)" - Clayton Caetano de Sousa]
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application