Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26184

Опубликовано: 21 мар. 2022
Источник: debian
EPSS Низкий

Описание

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
poetrynot-affectedpackage

EPSS

Процентиль: 69%
0.00597
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVSS3: 9.8
nvd
почти 4 года назад

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVSS3: 9.8
github
почти 4 года назад

Poetry before v1.1.9 contains Untrusted Search Path

EPSS

Процентиль: 69%
0.00597
Низкий