The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0.1"
}
]
}