PT-2024-1830 · Xml::Twig+3 · Xml::Twig+3

An Pham

·

Published

2024-01-17

·

Updated

2024-06-15

·

CVE-2024-23525

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spreadsheet::ParseXLSX versions prior to 0.30
Description The issue is related to the incorrect restriction of XML links to external objects, allowing an attacker to conduct XXE attacks using a specially crafted XLSX file. This is because the Spreadsheet::ParseXLSX package neglects to use the no xxe option of XML::Twig.
Recommendations For versions prior to 0.30, update to version 0.30 or later to resolve the issue. As a temporary workaround, consider enabling the no xxe option of XML::Twig to prevent XXE attacks.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01575
CVE-2024-23525
DLA-3723-1
OPENSUSE-SU-2024:13760-1
USN-6769-1

Affected Products

Linuxmint
Spreadsheet::Parsexlsx
Ubuntu
Xml::Twig