PT-2021-24447 · Unknown · Openapi-Cli

Published

2021-10-12

·

Updated

2021-10-12

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: openapi-cli versions prior to 1.0.0-beta.59
Description: The issue allows path traversal when the preview-docs command is executed in a directory containing files with a question mark ? in their name, provided the attacker is aware of the file name.
Recommendations: For versions prior to 1.0.0-beta.59, update to version 1.0.0-beta.59 or later to resolve the issue. As a temporary workaround, do not run the preview-docs command in folders that contain files with a question mark ? in their name.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-Q324-Q795-2Q5P

Affected Products

Openapi-Cli