SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely
Critical severity
GitHub Reviewed
Published
Jul 12, 2022
to the GitHub Advisory Database
•
Updated Sep 2, 2023
Description
Published by the National Vulnerability Database
Jul 11, 2022
Published to the GitHub Advisory Database
Jul 12, 2022
Reviewed
Jul 21, 2022
Last updated
Sep 2, 2023
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. A patch is available on the
master
branch of the repository.References