Safety vulnerability ID: 50275
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Untangle 1.2.1 includes a fix for CVE-2022-33977: Untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
Latest version: 1.2.1
Converts XML to Python objects
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running. See CVE-2022-33977.
MISC:https://github.com/stchris/untangle: https://github.com/stchris/untangle
MISC:https://github.com/stchris/untangle/releases/tag/1.2.1: https://github.com/stchris/untangle/releases/tag/1.2.1
MISC:https://jvn.jp/en/jp/JVN30454777/: https://jvn.jp/en/jp/JVN30454777/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application