EPSS
Percentile
76.4%
An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
github.com/geopython/OWSLib/issues/790
github.com/geopython/pywps
github.com/geopython/pywps/pull/616
lists.debian.org/debian-lts-announce/2021/09/msg00001.html
nvd.nist.gov/vuln/detail/CVE-2021-39371