CVE-2021-39371

An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
References
Link Resource
https://github.com/geopython/OWSLib/issues/790 Issue Tracking Patch Third Party Advisory
https://github.com/geopython/pywps/pull/616 Patch Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:osgeo:owslib:0.24.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:pywps:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

02 Jun 2022, 14:48

Type Values Removed Values Added
First Time Osgeo owslib
CPE cpe:2.3:a:github:owslib:0.24.1:*:*:*:*:*:*:* cpe:2.3:a:osgeo:owslib:0.24.1:*:*:*:*:*:*:*

14 Sep 2021, 18:46

Type Values Removed Values Added
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

10 Sep 2021, 14:15

Type Values Removed Values Added
Summary An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected. An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.

04 Sep 2021, 13:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/09/msg00001.html -

26 Aug 2021, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:a:github:owslib:0.24.1:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:pywps:*:*:*:*:*:*:*:*
References (MISC) https://github.com/geopython/pywps/pull/616 - (MISC) https://github.com/geopython/pywps/pull/616 - Patch, Third Party Advisory
References (MISC) https://github.com/geopython/OWSLib/issues/790 - (MISC) https://github.com/geopython/OWSLib/issues/790 - Issue Tracking, Patch, Third Party Advisory
CWE CWE-611

23 Aug 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-23 01:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-39371

Mitre link : CVE-2021-39371

CVE.ORG link : CVE-2021-39371


JSON object : View

Products Affected

osgeo

  • owslib
  • pywps

debian

  • debian_linux
CWE
CWE-611

Improper Restriction of XML External Entity Reference