CVE-2017-5992 - CERT CVE
ID CVE-2017-5992
Sažetak Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.
Reference
CVSS
Base: 5.8
Impact: 4.9
Exploitability:8.6
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE PARTIAL
CVSS vektor AV:N/AC:M/Au:N/C:P/I:N/A:P
Zadnje važnije ažuriranje 17-02-2017 - 14:00
Objavljeno 15-02-2017 - 19:59