CVE-2022-31531

CRITICAL Year: 2022
CVSS v3 Score
9.3
Critical
CVSS v2 Score
6.4
Medium

Vulnerability Description

The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS:9.3(Critical)

Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, ...

CWE-222020
CVSS:9.3(Critical)

The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022