← Volver a CVEs
CVE-2020-27197
CRITICAL9.8
Descripcion
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado10/17/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
eclecticiq:opentaxiilibtaxii_project:libtaxii
Debilidades (CWE)
CWE-918
Referencias
http://packetstormsecurity.com/files/159662/Libtaxii-1.1.117-OpenTaxi-0.2.0-Server-Side-Request-Forgery.html(cve@mitre.org)
https://github.com/TAXIIProject/libtaxii/issues/246(cve@mitre.org)
https://github.com/eclecticiq/OpenTAXII/issues/176(cve@mitre.org)
http://packetstormsecurity.com/files/159662/Libtaxii-1.1.117-OpenTaxi-0.2.0-Server-Side-Request-Forgery.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/TAXIIProject/libtaxii/issues/246(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/eclecticiq/OpenTAXII/issues/176(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.