VulnerabilityModified
CVE-2021-23418
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
CRITICAL 9.8EPSS 1.64%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- glances project/glances
- Source
- report@snyk.io
References
- https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94Patch, Third Party Advisory
- https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07aPatch, Third Party Advisory
- https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32Patch, Third Party Advisory
- https://github.com/nicolargo/glances/issues/1025Exploit, Issue Tracking, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807Patch, Third Party Advisory
- https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94Patch, Third Party Advisory
- https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07aPatch, Third Party Advisory
- https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32Patch, Third Party Advisory
- https://github.com/nicolargo/glances/issues/1025Exploit, Issue Tracking, Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.