libtaxii
TAXII 1.X Library.
Activity
- Latest release
- 5y ago
- Total releases
- 28
- Cadence
- ~3 months
- Last 12 months
- 0
Details
- License
- BSD-3-Clause
- First release
- May 31, 2013
| Version | Released | |
|---|---|---|
1.1.119
patch
|
1.1.119
patch
Dependencies (3)
|
|
1.1.118
patch
|
1.1.118
patch
Dependencies (3)
|
|
1.1.117
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.117
patch
Dependencies (3)
|
|
1.1.116
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.116
patch
Dependencies (3)
|
|
1.1.115
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.115
patch
Dependencies (3)
|
|
1.1.114
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.114
patch
Dependencies (3)
|
|
1.1.113
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.113
patch
Dependencies (3)
|
|
1.1.112
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.112
patch
Dependencies (3)
|
|
1.1.111
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.111
patch
Dependencies (3)
|
|
1.1.110
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.110
patch
|
|
1.1.109
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.109
patch
|
|
1.1.108
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.108
patch
|
|
1.1.107
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.107
patch
|
|
1.1.106
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.106
patch
|
|
1.1.105
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.105
patch
|
|
1.1.104
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.104
patch
|
|
1.1.103
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.103
patch
|
|
1.1.102
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.102
patch
|
|
1.1.101
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.101
patch
|
|
1.1.100
minor
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.1.100
minor
|
|
1.0.107
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.107
patch
|
|
1.0.106
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.106
patch
|
|
1.0.105
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.105
patch
|
|
1.0.104
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.104
patch
|
|
1.0.103
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.103
patch
|
|
1.0.101
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.101
patch
|
|
1.0.100
patch
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.100
patch
|
|
1.0.090
initial
1 CVE
CVE-2020-27197
GHSA-836c-xg97-8p4h
PYSEC-2020-59
Apr 30, 2021
libtaxii Server-Side Request Forgery vulnerability
Critical
Network
Low
None
None
"TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group."" Affected versions
1.0.090
1.0.100
1.0.101
1.0.103
1.0.104
1.0.105
1.0.106
1.0.107
1.1.100
1.1.101
1.1.102
1.1.103
+ 14 more Show less
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
Fixed in
1.1.118
References
Updated Feb 18, 2025 · Source: OSV.dev |
1.0.090
initial
|