PT-2021-24447 · Unknown · Openapi-Cli
Published
2021-10-12
·
Updated
2021-10-12
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
openapi-cli versions prior to 1.0.0-beta.59
Description:
The issue allows path traversal when the
preview-docs command is executed in a directory containing files with a question mark ? in their name, provided the attacker is aware of the file name.Recommendations:
For versions prior to 1.0.0-beta.59, update to version 1.0.0-beta.59 or later to resolve the issue.
As a temporary workaround, do not run the
preview-docs command in folders that contain files with a question mark ? in their name. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openapi-Cli