Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr2c-5w89-63pv

Опубликовано: 23 мар. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Poetry before v1.1.9 contains Untrusted Search Path

Poetry prior to v1.1.9 was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Пакеты

Наименование

poetry

pip
Затронутые версииВерсия исправления

< 1.1.9

1.1.9

EPSS

Процентиль: 69%
0.00597
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVSS3: 9.8
nvd
почти 4 года назад

Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

CVSS3: 9.8
debian
почти 4 года назад

Poetry v1.1.9 and below was discovered to contain an untrusted search ...

EPSS

Процентиль: 69%
0.00597
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-426