Описание
SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. A patch is available on the master branch of the repository.
Пакеты
Наименование
opendiamond
pip
Затронутые версииВерсия исправления
<= 10.1.1
Отсутствует
Связанные уязвимости
CVSS3: 9.3
nvd
больше 3 лет назад
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.