CVE-2020-27197
Last modified
CVE-2020-27197 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... EPSS estimates a 2.25% chance of exploitation in the next 30 days.
Description
TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclecticiq | Opentaxii | <= 0.2.0 |
| Libtaxii Project | Libtaxii | <= 1.1.117 |
References
- https://packetstormsecurity.com/files/159662/Libtaxii-1.1.117-OpenTaxi-0.2.0-Server-Side-Request-Forgery.htmlExploit, Third Party Advisory
- https://github.com/TAXIIProject/libtaxii/issues/246Exploit, Third Party Advisory
- https://github.com/eclecticiq/OpenTAXII/issues/176Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/159662/Libtaxii-1.1.117-OpenTaxi-0.2.0-Server-Side-Request-Forgery.htmlExploit, Third Party Advisory
- https://github.com/TAXIIProject/libtaxii/issues/246Exploit, Third Party Advisory
- https://github.com/eclecticiq/OpenTAXII/issues/176Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27197?
How severe is CVE-2020-27197?
How do I fix CVE-2020-27197?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27191LionWiki before 3.2.12 allows an unauthenticated user to rea…7.5
- CVE-2020-27192BinaryNights ForkLift 3.4 was compiled with the com.apple.se…7.8
- CVE-2020-27193A cross-site scripting (XSS) vulnerability in the Color Dial…6.1
- CVE-2020-27194An issue was discovered in the Linux kernel before 5.8.15. s…5.5
- CVE-2020-27195HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.1…9.1
- CVE-2020-27196An issue was discovered in PlayJava in Play Framework 2.6.0 …7.5
- CVE-2020-27199The Magic Home Pro application 1.5.1 for Android allows Auth…7.5
- CVE-2020-2720Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…5.4
- CVE-2020-27207Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, rel…7.5
- CVE-2020-27208The flash read-out protection (RDP) level is not enforced du…6.8
- CVE-2020-27209The ECDSA operation of the micro-ecc library 1.0 is vulnerab…7.5
- CVE-2020-2721Vulnerability in the Oracle FLEXCUBE Investor Servicing prod…6.5
Are you affected by CVE-2020-27197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
