PT-2020-14221 · Unknown · Openapi-Python-Client
Published
2020-08-14
·
Updated
2020-08-20
·
CVE-2020-15141
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
openapi-python-client versions prior to 0.5.3
Description
The issue allows for a path traversal vulnerability. If a user generates a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
Recommendations
For versions prior to 0.5.3, update to version 0.5.3 once it is released, as a fix is being worked on for this version.
As a temporary workaround, inspect OpenAPI documents before generating clients for them.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openapi-Python-Client