CVE-2022-31584

CRITICAL Year: 2022
CVSS v3 Score
9.3
Critical
CVSS v2 Score
6.4
Medium

Vulnerability Description

The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS:9.3(Critical)

Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, ...

CWE-222020
CVSS:9.3(Critical)

The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022
CVSS:9.3(Critical)

The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CWE-222022