Описание
In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.5.3 (исключая)
cpe:2.3:a:openapi-python-client_project:openapi-python-client:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00362
Низкий
3 Low
CVSS3
4.1 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 58%
0.00362
Низкий
3 Low
CVSS3
4.1 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22