VDB
Sign up
—

PYSEC-2017-48

Quick fix

PYSEC-2017-48 — openpyxl: upgrade to the fixed version with the command below.

pip install --upgrade 'openpyxl>=2.4.1'

Details

Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/openpyxl
Introduced in: 0Fixed in: 2.4.1
Fixpip install --upgrade 'openpyxl>=2.4.1'

References