PYSEC-2019-253

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/tahoe-lafs/PYSEC-2019-253.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2019-253
Withdrawn
2024-11-22T04:37:05Z
Published
2019-11-07T18:15:00Z
Modified
2024-12-19T05:47:49.035329Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

References

Affected packages

PyPI / tahoe-lafs

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
0
1.*
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.1
1.16.0
1.17.0
1.17.1
1.18.0
1.19.0
1.20.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/tahoe-lafs/PYSEC-2019-253.yaml"