CVE-2017-5992 PUBLISHED

Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

EPSS 0.53% · 67.0th percentile

Risk Scores

EPSS Score
0.53%
67.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSopenpyxl0, 2.3.0~b1-1ubuntu1, 2.3.0-1

Timeline

References

Open in Interactive Console →