Safety vulnerability ID: 50019
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ganga 8.5.10 includes a fix for CVE-2022-31507: Ganga before 8.5.10 allows absolute path traversal because the Flask send_file function is used unsafely.
Latest version: 8.7.9
Job management tool
The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. See CVE-2022-31507.
MISC:https://github.com/ganga-devs/ganga/commit/730e7aba192407d35eb37dd7938d49071124be8c: https://github.com/ganga-devs/ganga/commit/730e7aba192407d35eb37dd7938d49071124be8c
MISC:https://github.com/ganga-devs/ganga/releases/tag/8.5.10: https://github.com/ganga-devs/ganga/releases/tag/8.5.10
MISC:https://github.com/github/securitylab/issues/669#issuecomment-1117265726: https://github.com/github/securitylab/issues/669#issuecomment-1117265726
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application