CVE-2022-48565
Dashboard / Vulnerabilities / CVE-2022-48565
CVE-2022-48565
Summary:
Details: An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
References: https://bugs.python.org/issue42051, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48565.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/, https://nvd.nist.gov/vuln/detail/CVE-2022-48565, https://security.netapp.com/advisory/ntap-20231006-0007/, https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html, https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
Affected packages
Package
Name:
Purl:
