CVE-2022-48565

Updated: 2023-09-20 20:59:06.177174

Description:

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x CRITICAL 9.8

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 7 ELS python3 3.6.8 9.8 CRITICAL In Testing 2023-09-19 14:07:43
CentOS 8.4 ELS python3 3.6.8 9.8 CRITICAL Released CLSA-2023:1693986539 2023-09-06 05:06:45
CentOS 8.5 ELS python3 3.6.8 9.8 CRITICAL Released CLSA-2023:1693986821 2023-09-06 05:06:44
Ubuntu 16.04 ELS python2.7 2.7.12 9.8 CRITICAL Released CLSA-2023:1694538236 2023-09-12 14:06:28
Ubuntu 16.04 ELS python3.5 3.5.2 9.8 CRITICAL Released CLSA-2023:1694538434 2023-09-12 14:06:26
Ubuntu 18.04 ELS python2.7 2.7.17-1 9.8 CRITICAL Released CLSA-2023:1694538765 2023-09-12 14:06:27
Ubuntu 18.04 ELS python3.6 3.6.9-1 9.8 CRITICAL Released CLSA-2023:1694538837 2023-09-12 14:06:25