CVE-2023-45139

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-45139
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-45139.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-45139
Aliases
Downstream
Related
Published
2024-01-10T16:03:08.770Z
Modified
2025-11-28T05:36:25.291797Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
fonttools XML External Entity Injection (XXE) Vulnerability
Details

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve arbitrary entities when a candidate font (OT-SVG fonts), which contains a SVG table, is parsed. This allows attackers to include arbitrary files from the filesystem fontTools is running on or make web requests from the host system. This vulnerability has been patched in version 4.43.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-611"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45139.json"
}
References

Affected packages

Git / github.com/fonttools/fonttools

Affected ranges

Type
GIT
Repo
https://github.com/fonttools/fonttools
Events

Affected versions

4.*

4.28.2
4.28.3
4.28.4
4.28.5
4.29.0
4.29.1
4.30.0
4.31.0
4.31.1
4.31.2
4.32.0
4.33.0
4.33.1
4.33.3
4.34.0
4.34.1
4.34.2
4.34.3
4.34.4
4.35.0
4.36.0
4.37.0
4.37.1
4.37.2
4.37.3
4.37.4
4.38.0
4.39.0
4.39.1
4.39.2
4.39.3
4.39.4
4.40.0
4.41.0
4.41.1
4.42.0
4.42.1