Tooxie Shiva 0.10.0 allows absolute path traversal because Flask send_file function used unsafely
Critical severity
GitHub Reviewed
Published
Jul 12, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jul 11, 2022
Published to the GitHub Advisory Database
Jul 12, 2022
Reviewed
Jul 21, 2022
Last updated
Jan 27, 2023
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
References