An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
| Software | From | Fixed in |
|---|---|---|
| osgeo / owslib | 0.24.1 | 0.24.1.x |
| osgeo / pywps | - | 4.4.5 |
| debian / debian_linux | 9.0 | 9.0.x |
pywps
|
- | 4.5.0 |