All errata/sisyphus/ALT-PU-2019-4197-1
ALT-PU-2019-4197-1

Package update python-module-openpyxl in branch sisyphus

Version2.6.2-alt1
Published2019-08-29
Max severityHIGH
Severity:

Closed issues (2)

CVE-2017-5992
HIGH8.2

Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

Published: 2017-02-15Modified: 2025-04-20
CVSS 2.0MEDIUM 5.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:P
CVSS 3.xHIGH 8.2
CVSS:3.x/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H