CVE-2021-39371: XML External Entity Injection in PyWPS
(updated )
An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
References
- github.com/advisories/GHSA-p9wf-3xpg-c9g5
- github.com/geopython/OWSLib/issues/790
- github.com/geopython/pywps
- github.com/geopython/pywps/commit/7d6b26a2e931df2feca0b7fb24f4d01610825aee
- github.com/geopython/pywps/pull/616
- github.com/pypa/advisory-database/tree/main/vulns/pywps/PYSEC-2021-121.yaml
- lists.debian.org/debian-lts-announce/2021/09/msg00001.html
- nvd.nist.gov/vuln/detail/CVE-2021-39371
Detect and mitigate CVE-2021-39371 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →