Sploitus

CVE-2020-27197

1 known exploit for CVE-2020-27197

TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.

Affected products
Opentaxii, Libtaxii, Lxml
Eclecticiq Opentaxii
≤ 0.2.0
Libtaxii Project Libtaxii
≤ 1.1.117
CVSS 3.1
9.8 CRITICAL
EPSS
2.3% (82th percentile)
Weakness
CWE-918
NVD status
Modified
Published
2020-10-17
CVE-2020-27197 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2020-27197

Proof-of-concept code and exploit modules indexed by Sploitus