{"id":"PYSEC-2020-339","details":"XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.","aliases":["CVE-2015-8549","GHSA-m7m4-4vm8-55wg"],"modified":"2023-11-08T03:58:02.455853Z","published":"2020-01-15T15:15:00Z","references":[{"type":"WEB","url":"http://www.securityfocus.com/archive/1/archive/1/537151/100/0/threaded"},{"type":"WEB","url":"https://github.com/hydralabs/pyamf/releases/tag/v0.8.0"},{"type":"WEB","url":"https://github.com/hydralabs/pyamf/pull/58"},{"type":"ADVISORY","url":"http://www.ocert.org/advisories/ocert-2015-011.html"},{"type":"PACKAGE","url":"https://pypi.org/project/pyamf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8549"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m7m4-4vm8-55wg"}],"affected":[{"package":{"name":"pyamf","ecosystem":"PyPI","purl":"pkg:pypi/pyamf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0"}]}],"versions":["0.4.2","0.5","0.5.1","0.6","0.6.1","0.6.1.1","0.6b2","0.7.0","0.7.1","0.7.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pyamf/PYSEC-2020-339.yaml"}}],"schema_version":"1.7.3"}