PyPi: Glances

CVE-2021-23418

Safety vulnerability ID: 41042

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jul 29, 2021 Updated at May 12, 2024
Scan your Python projects for vulnerabilities →

Advisory

Glances before version 3.2.1 is vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks. See: CVE-2021-23418.

Affected package

glances

Latest version: 4.0.1

A cross-platform curses-based monitoring tool

Affected versions

Fixed versions

Vulnerability changelog

The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is known to be vulnerable to XML attacks. See CVE-2021-23418.


MISC:https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94: https://github.com/nicolargo/glances/commit/4b87e979afdc06d98ed1b48da31e69eaa3a9fb94
MISC:https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a: https://github.com/nicolargo/glances/commit/85d5a6b4af31fcf785d5a61086cbbd166b40b07a
MISC:https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32: https://github.com/nicolargo/glances/commit/9d6051be4a42f692392049fdbfc85d5dfa458b32
MISC:https://github.com/nicolargo/glances/issues/1025: https://github.com/nicolargo/glances/issues/1025
MISC:https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807: https://snyk.io/vuln/SNYK-PYTHON-GLANCES-1311807

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH

CVSS v2 Details

HIGH 7.5
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL