Vulnerability Description
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | < 3.6.13 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://bugs.python.org/issue42051ExploitIssue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20231006-0007/
- https://bugs.python.org/issue42051ExploitIssue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2023/09/msg00022.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.netapp.com/advisory/ntap-20231006-0007/
FAQ
What is CVE-2022-48565?
CVE-2022-48565 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
How severe is CVE-2022-48565?
CVE-2022-48565 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-48565?
Check the references section above for vendor advisories and patch information. Affected products include: Python Python, Debian Debian Linux.