Safety vulnerability ID: 50274
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Untangle 1.2.1 includes a fix for CVE-2022-31471: Untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
Latest version: 1.2.1
Converts XML to Python objects
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files. See CVE-2022-31471.
MISC:https://github.com/stchris/untangle: https://github.com/stchris/untangle
MISC:https://github.com/stchris/untangle/releases/tag/1.2.1: https://github.com/stchris/untangle/releases/tag/1.2.1
MISC:https://jvn.jp/en/jp/JVN30454777/: https://jvn.jp/en/jp/JVN30454777/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application