python: XML External Entity in XML processing plistlib module
Published Aug 22, 2023
9.8
CRITICALCVSS 3.1
EPSS 5.07%
Description
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
python27:2.7-8100020240208011952.5f0f67de
Fixed · RHSA-2024:2987
Red Hat Enterprise Linux 6
python
Out of support scope
Red Hat Enterprise Linux 7
python
Out of support scope
Red Hat Enterprise Linux 7
python3
Out of support scope
Red Hat Enterprise Linux 8
gimp:flatpak/python2
Affected
Red Hat Enterprise Linux 8
inkscape:flatpak/python2
Will not fix
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python3.11
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python39:3.9/python39
Not affected
Red Hat Enterprise Linux 9
python3.11
Not affected
Red Hat Enterprise Linux 9
python3.9
Not affected
Red Hat Software Collections
rh-python38-python
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python27:2.7-8100020240208011952.5f0f67de | Fixed | RHSA-2024:2987 |
| Red Hat Enterprise Linux 6 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | gimp:flatpak/python2 | Affected | n/a |
| Red Hat Enterprise Linux 8 | inkscape:flatpak/python2 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.9 | Not affected | n/a |
| Red Hat Software Collections | rh-python38-python | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is classified as Moderate according to Red Hat's Severity Rating Classification, as in contrast to an Important severity rating, the conditions to exploit this vulnerability makes it highly improbable for a general remote use case to lead to arbitrary code execution or affect data integrity and the highest impact is data disclosure and application crash. The versions of python as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 9 either has fixed code or they just provide `symlinks` to the main `python3` component, which provides the interpreter of the Python programming language. Therefore, both Red Hat Enterprise Linux versions 8 and 9 are not affected. https://access.redhat.com/security/updates/classification
Red Hat mitigation
The XML modules in python are not secure against erroneous or maliciously constructed data. If you need to parse untrusted or unauthenticated data, see the XML vulnerabilities and the defusedxml package sections. https://docs.python.org/dev/library/xml.html
References (12)
- https://access.redhat.com/security/cve/CVE-2022-48565 Vendor Advisory
- https://bugs.python.org/issue42051 ExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2240059 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51261 Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html mailing-listThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-48565
- https://security.netapp.com/advisory/ntap-20231006-0007/
- https://www.cve.org/CVERecord?id=CVE-2022-48565
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data