Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj8w-rv5x-2v9h

Опубликовано: 01 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Duplicate Advisory: Starlette vulnerable to directory traversal

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-v5gw-mw7f-84px. This link is maintained to preserve external references.

Original Description

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.

Пакеты

Наименование

starlette

pip
Затронутые версииВерсия исправления

>= 0.13.5, < 0.27.0

0.27.0

7.5 High

CVSS3

Дефекты

CWE-22

7.5 High

CVSS3

Дефекты

CWE-22