This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:bikeshed_project:bikeshed:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "3.0.0"
}
],
"source": "CPE_RANGE",
"vendor_product": "bikeshed_project:bikeshed"
},
{
"extracted_events": [
{
"fixed": "3.0.0"
}
],
"source": "DESCRIPTION"
}
]
}