PYSEC-2020-70

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/openapi-python-client/PYSEC-2020-70.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2020-70
Aliases
Published
2020-08-14T17:15:00Z
Modified
2023-11-08T04:02:30.943540Z
Summary
[none]
Details

In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

References

Affected packages

PyPI / openapi-python-client

Package

Name
openapi-python-client
View open source insights on deps.dev
Purl
pkg:pypi/openapi-python-client

Affected ranges

Type
GIT
Repo
https://github.com/triaxtec/openapi-python-client
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3

Affected versions

0.*

0.1.0.dev0
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.3.0
0.4.0rc1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2