XML External Entity Reference in Glances
Moderate severity
GitHub Reviewed
Published
Aug 9, 2021
to the GitHub Advisory Database
•
Updated Sep 20, 2024
Description
Published by the National Vulnerability Database
Jul 29, 2021
Reviewed
Aug 2, 2021
Published to the GitHub Advisory Database
Aug 9, 2021
Last updated
Sep 20, 2024
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
References