PT-2020-12331 · Python · Svgalib
Mrlion9
·
Published
2020-03-20
·
Updated
2021-05-06
·
CVE-2020-10799
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
svglib versions through 0.9.3
Description
The issue allows XXE attacks via an
svg2rlg call. This affects the svglib package for Python.Recommendations
For versions through 0.9.3, consider disabling the
svg2rlg call as a temporary workaround until a patch is available. Restrict access to the svglib package to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Svgalib