CVE-2020-5227
Last modified
CVE-2020-5227 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks (e.g. XML Bomb). This becomes a concern in particular if feedgen is used to include content from untrused sources and if XML (including XHTML) is directly included instead of providing plain tex content only. This problem has been fixed in feedgen 0.9.0 which disallows XML entity expansion and external resources.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Feedgen Project | Feedgen | < 0.9.0 |
References
- https://docs.microsoft.com/en-us/archive/msdn-magazine/2009/november/xml-denial-of-service-attacks-and-defensesExploit, Patch, Third Party Advisory, Vendor Advisory
- https://docs.microsoft.com/en-us/archive/msdn-magazine/2009/november/xml-denial-of-service-attacks-and-defensesExploit, Patch, Third Party Advisory, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5227?
How severe is CVE-2020-5227?
How do I fix CVE-2020-5227?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-5221In uftpd before 2.11, it is possible for an unauthenticated …7.2
- CVE-2020-5222Opencast before 7.6 and 8.1 enables a remember-me cookie bas…8.8
- CVE-2020-5223In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before …4.4
- CVE-2020-5224In Django User Sessions (django-user-sessions) before 1.7.1,…8.8
- CVE-2020-5225Log injection in SimpleSAMLphp before version 1.18.4. The ww…5.4
- CVE-2020-5226Cross-site scripting in SimpleSAMLphp before version 1.18.4.…5.4
- CVE-2020-5228Opencast before 8.1 and 7.6 allows unauthorized public acces…7.5
- CVE-2020-5229Opencast before 8.1 stores passwords using the rather outdat…8.1
- CVE-2020-5230Opencast before 8.1 and 7.6 allows almost arbitrary identifi…7.5
- CVE-2020-5231In Opencast before 7.6 and 8.1, users with the role ROLE_COU…6.5
- CVE-2020-5232A user who owns an ENS domain can set a trapdoor, allowing t…8.7
- CVE-2020-5233OAuth2 Proxy before 5.0 has an open redirect vulnerability. …6.1
Are you affected by CVE-2020-5227?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
