The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0453 | The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the \"undo archive operation\" feature. |
Github GHSA |
GHSA-8wwf-2644-f8x4 | The Fuck Arbitrary File Deletion via Path Traversal |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:12:50.063Z
Reserved: 2021-06-09T00:00:00.000Z
Link: CVE-2021-34363
No data.
Status : Modified
Published: 2021-06-10T11:15:09.357
Modified: 2024-11-21T06:10:14.617
Link: CVE-2021-34363
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA