—
PYSEC-2023-41
Quick fix
PYSEC-2023-41 — pretalx: upgrade to the fixed version with the command below.
pip install --upgrade 'pretalx>=60722c43cf975f319e94102e6bff320723776890'Details
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pretalx
Introduced in:
0Fixed in: 60722c43cf975f319e94102e6bff320723776890Fix
pip install --upgrade 'pretalx>=60722c43cf975f319e94102e6bff320723776890'References
- https://github.com/pretalx/pretalx/commit/60722c43cf975f319e94102e6bff320723776890[FIX]
- https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/[ARTICLE]
- https://github.com/pretalx/pretalx/releases/tag/v2.3.2[WEB]
- https://pretalx.com/p/news/security-release-232/[WEB]
- https://github.com/advisories/GHSA-wh3w-jcc7-mhmf[ADVISORY]