PT-2020-12331 · Python · Svgalib

Mrlion9

·

Published

2020-03-20

·

Updated

2021-05-06

·

CVE-2020-10799

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions svglib versions through 0.9.3
Description The issue allows XXE attacks via an svg2rlg call. This affects the svglib package for Python.
Recommendations For versions through 0.9.3, consider disabling the svg2rlg call as a temporary workaround until a patch is available. Restrict access to the svglib package to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10799
GHSA-3VCG-8P79-JPCV
PYSEC-2020-111

Affected Products

Svgalib