First published: Tue Aug 22 2023(Updated: )
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python Python | <3.6.13 | |
Python Python | >=3.7.0<3.7.10 | |
Python Python | >=3.8.0<3.8.7 | |
Python Python | >=3.9.0<3.9.1 | |
Debian Debian Linux | =10.0 | |
redhat/python | <3.10.0 | 3.10.0 |
redhat/python | <3.9.1 | 3.9.1 |
redhat/python | <3.8.7 | 3.8.7 |
redhat/python | <3.7.10 | 3.7.10 |
redhat/python | <3.6.13 | 3.6.13 |
debian/pypy3 | 7.3.5+dfsg-2+deb11u2 7.3.5+dfsg-2+deb11u4 7.3.11+dfsg-2+deb12u2 7.3.17+dfsg-3 | |
debian/python2.7 | 2.7.18-8+deb11u1 | |
debian/python3.9 | 3.9.2-1 3.9.2-1+deb11u2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48565 is an XML External Entity (XXE) issue in Python through 3.9.1.
The severity of CVE-2022-48565 is critical with a severity value of 9.8.
CVE-2022-48565 affects Python through version 3.9.1.
Please update to the recommended versions: Python 2.7.17-1~18.04ubuntu1.13+ (Ubuntu Bionic), Python 2.7.6-8ubuntu0.6+ (Ubuntu Trusty), Python 2.7.12-1ubuntu0~16.04.18+ (Ubuntu Xenial), Python 3.5.2-2ubuntu0~16.04.13+ (Ubuntu Xenial), or Python 3.9.5-3~20.04.1 (Ubuntu Focal).
You can find more information about CVE-2022-48565 on the following references: [Link 1](https://bugs.python.org/issue42051), [Link 2](https://launchpad.net/bugs/cve/CVE-2022-48565), [Link 3](https://github.com/python/cpython/issues/86217).