ALT-PU-2021-2023-1
Closed vulnerabilities
Published: 2021-06-17
BDU:2021-04706
Уязвимость пакета TheFuck языка программирования Python, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании
Severity: CRITICAL (9.1)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References:
Published: 2021-06-10
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-34363
The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
Severity: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References:
- https://github.com/nvbn/thefuck/commit/e343c577cd7da4d304b837d4a07ab4df1e023092
- https://github.com/nvbn/thefuck/commit/e343c577cd7da4d304b837d4a07ab4df1e023092
- https://github.com/nvbn/thefuck/releases/tag/3.31
- https://github.com/nvbn/thefuck/releases/tag/3.31
- FEDORA-2022-0f1653e269
- FEDORA-2022-0f1653e269
- FEDORA-2022-5aeda24c24
- FEDORA-2022-5aeda24c24
- https://vuln.ryotak.me/advisories/48
- https://vuln.ryotak.me/advisories/48