aioxmpp@0.7.1 vulnerabilities

Pure-python XMPP library for asyncio

Direct Vulnerabilities

Known vulnerabilities in the aioxmpp package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Injection

aioxmpp is a pure-python XMPP library using the asyncio standard library module from Python 3.4.

Affected versions of this package are vulnerable to Arbitrary Code Injection due to an improper handling of structural elements in Stanza parser. A crafted stanza could be sent to an application which uses the vulnerable components to either inject data in a different context or cause the application to reconnect.

How to fix Arbitrary Code Injection?

Upgrade aioxmpp to version 0.10.3 or higher.

[,0.10.3)