Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wgr-7666-7pwj

Опубликовано: 20 авг. 2020
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 3

Описание

Path Traversal in openapi-python-client

Impact

Path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

Giving this a CVSS score of 3.0 (Low) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C

Patches

A fix is being worked on for version 0.5.3

Workarounds

Inspect OpenAPI documents before generating clients for them.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

openapi-python-client

pip
Затронутые версииВерсия исправления

< 0.5.3

0.5.3

EPSS

Процентиль: 58%
0.00362
Низкий

2.1 Low

CVSS4

3 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3
nvd
больше 5 лет назад

In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

EPSS

Процентиль: 58%
0.00362
Низкий

2.1 Low

CVSS4

3 Low

CVSS3

Дефекты

CWE-22