Vulnerability CVE-2020-27197


Published: 2020-10-17

Description:
** DISPUTED ** TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Libtaxii 1.1.117 / OpenTaxi 0.2.0 Server-Side Request Forgery
Owais Mehtab
22.10.2020

 References:
https://github.com/eclecticiq/OpenTAXII/issues/176
https://github.com/TAXIIProject/libtaxii/issues/246

Copyright 2024, cxsecurity.com

 

Back to Top