CVE-2022-31471 is an XML External Entity (XXE) vulnerability affecting untangle versions 1.2.0 and earlier, a Python library for converting XML to Python objects. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated remote attacker to read local files due to improper restriction of XML external entity references. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for data exfiltration remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:untangle_project:untangle:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.