Safety vulnerability ID: 25923
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Paste before 1.1 allowed escaping root and reading files when used with 'paste.httpserver…
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 3.10.1
Tools for using a Web Server Gateway Interface stack
--- * Security fix for ``paste.urlparser.StaticURLParser``. The problem allowed escap…
[This text has been limited. Please create a free account to view the full text.]
Create a free account to access detailed CVSS severity scores and full vulnerability advisories
Create free account