Skip to content

Avoid entity expansion attacks in Element Tree #68426

@vadmium

Description

@vadmium
BPO 24238
Nosy @tiran, @vadmium, @serhiy-storchaka
Files
  • etree_20130519.patch
  • etree-entities.v2.patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2015-05-19.11:17:59.200>
    labels = ['type-security', 'expert-XML']
    title = 'Avoid entity expansion attacks in Element Tree'
    updated_at = <Date 2016-06-04.06:48:58.706>
    user = 'https://github.com/vadmium'

    bugs.python.org fields:

    activity = <Date 2016-06-04.06:48:58.706>
    actor = 'martin.panter'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['XML']
    creation = <Date 2015-05-19.11:17:59.200>
    creator = 'martin.panter'
    dependencies = []
    files = ['39430', '43185']
    hgrepos = []
    issue_num = 24238
    keywords = ['patch']
    message_count = 2.0
    messages = ['243577', '267238']
    nosy_count = 3.0
    nosy_names = ['christian.heimes', 'martin.panter', 'serhiy.storchaka']
    pr_nums = []
    priority = 'normal'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue24238'
    versions = ['Python 3.6']

    Metadata

    Metadata

    Assignees

    No one assigned

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions