QID 983197
QID 983197: Python (pip) Security Update for openapi-python-client (GHSA-7wgr-7666-7pwj)
Security update has been released for openapi-python-client to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
Giving this a CVSS score of 3.0 (Low) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C
Solution
A fix is being worked on for version 0.5.3Workaround:
Inspect OpenAPI documents before generating clients for them.
Inspect OpenAPI documents before generating clients for them.
Vendor References
- GHSA-7wgr-7666-7pwj -
github.com/advisories/GHSA-7wgr-7666-7pwj
CVEs related to QID 983197
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7wgr-7666-7pwj | openapi-python-client |
|