GHSA-vpqp-hx68-p2wx

Suggest an improvement
Source
https://github.com/advisories/GHSA-vpqp-hx68-p2wx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vpqp-hx68-p2wx/GHSA-vpqp-hx68-p2wx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vpqp-hx68-p2wx
Aliases
Published
2022-05-14T01:08:23Z
Modified
2024-10-28T14:53:28.149849Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Improper Link Resolution Before File Access in Suds
Details

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

Database specific
{
    "nvd_published_at": "2013-09-23T20:55:00Z",
    "cwe_ids": [
        "CWE-59"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-08T19:12:30Z"
}
References

Affected packages

PyPI / suds

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0

Affected versions

0.*

0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4

Database specific

{
    "last_known_affected_version_range": "<= 0.4"
}

PyPI / suds-py3

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.4.1

Affected versions

1.*

1.0.0.0
1.3.1.0
1.3.2.0
1.3.3.0
1.3.4.0
1.4.0.0
1.4.1.0
1.4.2.0
1.4.3.0