Vulnerability GHSA-7wgr-7666-7pwj

Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
6 years ago
August 20, 2020 at 02:38 PM UTC
Path Traversal in openapi-python-client
0.1.0.dev0 - 0.5.2
0.1.0.dev0 - 0.5.2

Summary

Path Traversal in openapi-python-client

Details

Impact

Path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

Giving this a CVSS score of 3.0 (Low) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C

Patches

A fix is being worked on for version 0.5.3

Workarounds

Inspect OpenAPI documents before generating clients for them.

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
6 years ago
August 20, 2020 at 02:38 PM UTC
Fixed (0.5.3)
6 years ago
August 13, 2020 at 05:23 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:48 AM UTC