Filtered by vendor Sanic Project
Subscriptions
Filtered by product Sanic
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-35920 | 1 Sanic Project | 1 Sanic | 2024-11-21 | 8.3 High |
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue. | ||||
CVE-2017-16762 | 1 Sanic Project | 1 Sanic | 2024-11-21 | N/A |
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring. |
Page 1 of 1.