PT-2021-4116 · Pypi+1 · Thefuck+1

Ryotak

·

Published

2021-06-10

·

Updated

2024-12-19

·

CVE-2021-34363

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions TheFuck versions prior to 3.31
Description The issue is related to path traversal weaknesses in the TheFuck package for Python, allowing an attacker to compromise data integrity and cause a denial of service. This can lead to arbitrary file deletion via the "undo archive operation" feature. The package is designed to correct errors in previous console commands.
Recommendations For versions prior to 3.31, update to version 3.31 or later to resolve the issue. As a temporary workaround, consider disabling the undo archive operation feature until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2023
ALT-PU-2024-17193
BDU:2021-04706
CVE-2021-34363
GHSA-8WWF-2644-F8X4
PYSEC-2021-97

Affected Products

Alt Linux
Thefuck