Description
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6514 | Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue. |
Github GHSA |
GHSA-8cw9-5hmv-77w6 | sanic vulnerable to Path Traversal when using `app.static` if using encoded `%2F` URLs |
References
History
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T17:45:43.669Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-35920
Updated: 2024-08-03T09:51:58.602Z
Status : Modified
Published: 2022-08-01T22:15:10.347
Modified: 2024-11-21T07:11:57.880
Link: CVE-2022-35920
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA