untangle@0.3.1 vulnerabilities

Converts XML to Python objects

Direct Vulnerabilities

Known vulnerabilities in the untangle package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Improper Restriction of XML External Entity Reference

untangle is a library that converts XML to Python objects

Affected versions of this package are vulnerable to Improper Restriction of XML External Entity Reference due to improper neutralization of XML inputs. Exploiting this vulnerability allows an unauthenticated attacker to read the contents of local files.

How to fix Improper Restriction of XML External Entity Reference?

Upgrade untangle to version 1.2.1 or higher.

[,1.2.1)
  • M
XML Entity Expansion

untangle is a library that converts XML to Python objects

Affected versions of this package are vulnerable to XML Entity Expansion due to improper restriction recursive entity references in DTDs. Exploiting this vulnerability allows an attacker to cause a denial-of-service (DoS) condition on the server where the product is running.

How to fix XML Entity Expansion?

Upgrade untangle to version 1.2.1 or higher.

[,1.2.1)