sassoftware / python-sasctl

Import of method(s) from xml.etree detected BAN-B405
Security
Minor
10 months ago5 years old
Using xml.etree.ElementTree to parse untrusted XML data is known to be vulnerable to XML attacks. Replace xml.etree.ElementTree with the equivalent defusedxml package, or make sure defusedxml.defuse_stdlib() is called.
  1import os
  2import pickle
  3import xml.etree.ElementTree as etree  4from io import StringIO
  5
  6try: