Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqp6-6q54-7cxv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.

Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.8
redhat
около 4 лет назад

A flaw was found in python-babel. A path traversal vulnerability was found in how locale data files are checked and loaded within python-babel, allowing a local attacker to trick an application that uses python-babel to load a file outside of the intended locale directory. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.

nvd
около 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

rocky
больше 3 лет назад

Moderate: babel security and bug fix update

oracle-oval
больше 3 лет назад

ELSA-2021-4201: babel security and bug fix update (MODERATE)

rocky
больше 3 лет назад

Moderate: python27:2.7 security update

Дефекты

CWE-22