Vulnerability PYSEC-2020-70
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 years ago
August 14, 2020 at 05:15 PM UTC
No summary available
0.1.0.dev0 - 0.5.2
0.1.0.dev0 - 0.5.2
Details
In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
High Risk
6 years ago
openapi-python-client Arbitrary Code Generation vulnerability
0.1.0.dev0 - 0.5.2 GHSA-9x4c-63pf-525f
0.1.0.dev0 - 0.5.2 GHSA-9x4c-63pf-525f
Low Risk
6 years ago
Path Traversal in openapi-python-client
0.1.0.dev0 - 0.5.2 GHSA-7wgr-7666-7pwj
0.1.0.dev0 - 0.5.2 GHSA-7wgr-7666-7pwj
Unknown
6 years ago
No summary available
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
Impacted packages
Timeline
Published
6 years ago
August 14, 2020 at 05:15 PM UTC
Fixed (0.5.3)
6 years ago
August 13, 2020 at 05:23 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:02 AM UTC