Описание
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.3.10-3ubuntu0.1 |
| esm-infra-legacy/xenial | released | 1.0.3+ds1-1ubuntu1+esm2 |
| esm-infra/bionic | released | 1.0.7+ds1-1ubuntu0.2+esm1 |
| esm-infra/focal | released | 1.1.0+ds1-1ubuntu2.1+esm1 |
| esm-infra/xenial | released | 1.0.3+ds1-1ubuntu1+esm2 |
| jammy | released | 1.1.3+ds1-2ubuntu0.2 |
| noble | released | 1.3.2-1ubuntu0.1 |
| questing | released | 1.3.9-1ubuntu0.1 |
| resolute | released | 1.3.10-3ubuntu0.1 |
| upstream | released | 1.3.11 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
Mako is a template library written in Python. Prior to 1.3.11, Templat ...
EPSS
7.5 High
CVSS3