—
PYSEC-2006-1
Quick fix
PYSEC-2006-1 — cherrypy: upgrade to the fixed version with the command below.
pip install --upgrade 'cherrypy>=2.1.1'Details
Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099[WEB]
- http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306[WEB]
- http://www.securityfocus.com/bid/16760[WEB]
- http://www.cherrypy.org/[WEB]
- http://secunia.com/advisories/18944[ADVISORY]
- http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml[WEB]
- http://secunia.com/advisories/20344[ADVISORY]
- http://www.vupen.com/english/advisories/2006/0677[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24809[WEB]
- https://github.com/advisories/GHSA-vx77-5pf4-c9wr[ADVISORY]