MichaelDaum / spreadsheet-parsexlsx

parse XLSX files
http://metacpan.org/release/Spreadsheet-ParseXLSX
1 stars 3 forks source link

XXE in default configuration of Spreadsheet::ParseXLSX #10

Closed MichaelDaum closed 8 months ago

MichaelDaum commented 8 months ago

Don't allow external entities by default. Reported by @phvietan.

see https://gist.github.com/phvietan/d1c95a88ab6e17047b0248d6bf9eac4a

MichaelDaum commented 8 months ago

Fixed in latest release

stigtsp commented 8 months ago

CVE identifier has been requested

MichaelDaum commented 8 months ago

Reopening this issue to add the CVE id to the changelogs once available

carnil commented 8 months ago

CVE-2024-23525 has been assigned.

MichaelDaum commented 8 months ago

CVE now is properly documented in 0.31

phvietan commented 7 months ago

Thank you for your fast responses and hard work !!!