The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade signxml
to version 4.0.4 or higher.
signxml is a Python XML Signature and XAdES library
Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm due to the improper handling of signature verification settings when require_x509
is set to false and hmac_key
is specified. An attacker can manipulate the signature verification process by supplying a signature with an unexpected algorithm, leading to potential security breaches.
Note:
This is only exploitable if the user has not explicitly limited the expected signature algorithms using the expect_config
setting in signxml.XMLVerifier.verify
function.