CVE-2021-23418

Name
CVE-2021-23418
Description
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a
CONFIRM https://github.com/nicolargo/glances/issues/1025
CONFIRM https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807
CONFIRM https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32
CONFIRM https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:glances_project:glances:*:*:*:*:*:*:*:* glances >= None < 3.2.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
glances 3.14-community 3.1.7-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable