soappy
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting soappypage 1 of 1
- CVE-2014-3242NONECVSS 0.02014-05-12
vulnerable: 0.12.1, 0.12.3, 0.12.4, 0.12.5
SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- CVE-2014-3243NONECVSS 0.0✓ Fixed in 0.12.62014-05-12
vulnerable: 0.12.1, 0.12.3, 0.12.4, 0.12.5
SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity referen…
Check whether soappy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for soappy CVEs against the assets you own.
Start Free Scan →