CVE-2024-37388: ebookmeta XML External Entity vulnerability
(updated )
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata
function via lxml dependency allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.
References
Detect and mitigate CVE-2024-37388 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →