Safety vulnerability ID: 41208
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Latest version: 4.6.0
PyWPS is an implementation of the Web Processing Service standard from the Open Geospatial Consortium. PyWPS is written in Python.
An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected. See CVE-2021-39371.
MISC:https://github.com/geopython/OWSLib/issues/790: https://github.com/geopython/OWSLib/issues/790
MISC:https://github.com/geopython/pywps/pull/616: https://github.com/geopython/pywps/pull/616
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application