2 ms·
For those unfamiliar with these attack vectors, there code injection and denial-of-service issues that in previous version of Python, were exploitable by defaul
by ievans 5y ago
For those unfamiliar with these attack vectors, there code injection and denial-of-service issues that in previous version of Python, were exploitable by default. Projects like https://pypi.org/project/defusedxml/ https://pypi.org/project/defusedxml/ were designed to be secure against these issues by default, rather than requiring the library user to opt in.
The defusedxml project has an excellent matrix showing viability of the attack types against various python XML implementations: https://pypi.org/project/defusedxml/#python-xml-libraries https://pypi.org/project/defusedxml/#python-xml-libraries