—
PYSEC-2017-99
Quick fix
PYSEC-2017-99 — cherrymusic: upgrade to the fixed version with the command below.
pip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'Details
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/cherrymusic
Introduced in:
0Fixed in: 62dec34a1ea0741400dd6b6c660d303dcd651e86Fix
pip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'References
- https://www.exploit-db.com/exploits/40361/[WEB]
- https://github.com/devsnd/cherrymusic/issues/598[REPORT]
- https://github.com/devsnd/cherrymusic/commit/62dec34a1ea0741400dd6b6c660d303dcd651e86[FIX]
- http://www.fomori.org/cherrymusic/Changes.html[WEB]
- http://www.securityfocus.com/bid/97149[WEB]
- https://github.com/advisories/GHSA-q624-9634-77gh[ADVISORY]