Skip to content

Avoid entity expansion attacks in Element Tree #68426

@vadmium

Description

@vadmium
BPO 24238
Nosy @tiran, @vadmium, @serhiy-storchaka
Files
  • etree_20130519.patch
  • etree-entities.v2.patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None closed_at = None created_at = <Date 2015-05-19.11:17:59.200> labels = ['type-security', 'expert-XML'] title = 'Avoid entity expansion attacks in Element Tree' updated_at = <Date 2016-06-04.06:48:58.706> user = 'https://github.com/vadmium'

    bugs.python.org fields:

    activity = <Date 2016-06-04.06:48:58.706> actor = 'martin.panter' assignee = 'none' closed = False closed_date = None closer = None components = ['XML'] creation = <Date 2015-05-19.11:17:59.200> creator = 'martin.panter' dependencies = [] files = ['39430', '43185'] hgrepos = [] issue_num = 24238 keywords = ['patch'] message_count = 2.0 messages = ['243577', '267238'] nosy_count = 3.0 nosy_names = ['christian.heimes', 'martin.panter', 'serhiy.storchaka'] pr_nums = [] priority = 'normal' resolution = None stage = 'patch review' status = 'open' superseder = None type = 'security' url = 'https://bugs.python.org/issue24238' versions = ['Python 3.6']

    Metadata

    Metadata

    Assignees

    No one assigned

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions