Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-39371

An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-39371
  • Osgeo » Owslib » Version: 0.24.1
    cpe:2.3:a:osgeo:owslib:0.24.1
  • Osgeo » Pywps » Version: 3.0.0
    cpe:2.3:a:osgeo:pywps:3.0.0
  • Osgeo » Pywps » Version: 3.0.1
    cpe:2.3:a:osgeo:pywps:3.0.1
  • Osgeo » Pywps » Version: 3.1.0
    cpe:2.3:a:osgeo:pywps:3.1.0
  • Osgeo » Pywps » Version: 3.2.0
    cpe:2.3:a:osgeo:pywps:3.2.0
  • Osgeo » Pywps » Version: 3.2.1
    cpe:2.3:a:osgeo:pywps:3.2.1
  • Osgeo » Pywps » Version: 3.2.2
    cpe:2.3:a:osgeo:pywps:3.2.2
  • Osgeo » Pywps » Version: 3.2.3
    cpe:2.3:a:osgeo:pywps:3.2.3
  • Osgeo » Pywps » Version: 3.2.4
    cpe:2.3:a:osgeo:pywps:3.2.4
  • Osgeo » Pywps » Version: 3.2.5
    cpe:2.3:a:osgeo:pywps:3.2.5
  • Osgeo » Pywps » Version: 3.2.6
    cpe:2.3:a:osgeo:pywps:3.2.6
  • Osgeo » Pywps » Version: 4.0.0
    cpe:2.3:a:osgeo:pywps:4.0.0
  • Osgeo » Pywps » Version: 4.2.0
    cpe:2.3:a:osgeo:pywps:4.2.0
  • Osgeo » Pywps » Version: 4.2.1
    cpe:2.3:a:osgeo:pywps:4.2.1
  • Osgeo » Pywps » Version: 4.2.10
    cpe:2.3:a:osgeo:pywps:4.2.10
  • Osgeo » Pywps » Version: 4.2.11
    cpe:2.3:a:osgeo:pywps:4.2.11
  • Osgeo » Pywps » Version: 4.2.2
    cpe:2.3:a:osgeo:pywps:4.2.2
  • Osgeo » Pywps » Version: 4.2.3
    cpe:2.3:a:osgeo:pywps:4.2.3
  • Osgeo » Pywps » Version: 4.2.4
    cpe:2.3:a:osgeo:pywps:4.2.4
  • Osgeo » Pywps » Version: 4.2.5
    cpe:2.3:a:osgeo:pywps:4.2.5
  • Osgeo » Pywps » Version: 4.2.6
    cpe:2.3:a:osgeo:pywps:4.2.6
  • Osgeo » Pywps » Version: 4.2.7
    cpe:2.3:a:osgeo:pywps:4.2.7
  • Osgeo » Pywps » Version: 4.2.8
    cpe:2.3:a:osgeo:pywps:4.2.8
  • Osgeo » Pywps » Version: 4.2.9
    cpe:2.3:a:osgeo:pywps:4.2.9
  • Osgeo » Pywps » Version: 4.4.0
    cpe:2.3:a:osgeo:pywps:4.4.0
  • Osgeo » Pywps » Version: 4.4.1
    cpe:2.3:a:osgeo:pywps:4.4.1
  • Osgeo » Pywps » Version: 4.4.2
    cpe:2.3:a:osgeo:pywps:4.4.2
  • Osgeo » Pywps » Version: 4.4.3
    cpe:2.3:a:osgeo:pywps:4.4.3
  • Osgeo » Pywps » Version: 4.4.4
    cpe:2.3:a:osgeo:pywps:4.4.4
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved