Back

CRITICAL

python: XML External Entity in XML processing plistlib module

Published Aug 22, 2023

Description

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

Affected products

Remediation

Red Hat statement

This vulnerability is classified as Moderate according to Red Hat's Severity Rating Classification, as in contrast to an Important severity rating, the conditions to exploit this vulnerability makes it highly improbable for a general remote use case to lead to arbitrary code execution or affect data integrity and the highest impact is data disclosure and application crash. The versions of python as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 9 either has fixed code or they just provide `symlinks` to the main `python3` component, which provides the interpreter of the Python programming language. Therefore, both Red Hat Enterprise Linux versions 8 and 9 are not affected. https://access.redhat.com/security/updates/classification

Red Hat mitigation

The XML modules in python are not secure against erroneous or maliciously constructed data. If you need to parse untrusted or unauthenticated data, see the XML vulnerabilities and the defusedxml package sections. https://docs.python.org/dev/library/xml.html

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Aug 22, 2023
Updated Oct 3, 2024
Reserved Jul 23, 2023

CISA Vulnrichment

Updated Oct 3, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Aug 22, 2023
Bugzilla 2240059

ENISA EUVD

Assigner mitre
Published Aug 22, 2023
Updated Oct 3, 2024

GitHub

No data