ZeroHour

CVE-2022-48565

PoC
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

Vendors
pythondebian
Products
python, debian linux
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.