An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
| Software | From | Fixed in |
|---|---|---|
| python / python | 3.7.0 | 3.7.10 |
| python / python | - | 3.6.13 |
| python / python | 3.9.0 | 3.9.1 |
| python / python | 3.8.0 | 3.8.7 |
| debian / debian_linux | 10.0 | 10.0.x |