UNKNOWN PyPI
unstructured XML External Entity (XXE)
GHSA-32r8-54hf-c9p3 · CVE-2024-46455 · GO-2024-3315
Published · Modified
Description
unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-46455
- WEB https://github.com/Unstructured-IO/unstructured/pull/3088
- WEB https://github.com/Unstructured-IO/unstructured/commit/171b5df09fc3346aba8ce91c04de5b3e094a86bd
- WEB https://binarysouljour.me/cve-2024-46455
- PACKAGE https://github.com/Unstructured-IO/unstructured
- WEB https://www.tenable.com/cve/CVE-2024-46455
Ready to move
Start Securing
Free, no credit card | First findings in minutes