The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
References
Link | Resource |
---|---|
https://vuln.ryotak.me/advisories/48 | Third Party Advisory |
https://github.com/nvbn/thefuck/commit/e343c577cd7da4d304b837d4a07ab4df1e023092 | Patch Third Party Advisory |
https://github.com/nvbn/thefuck/releases/tag/3.31 | Release Notes Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MEDDLBFVRUQHPYIBJ4MFM3M4NUJUXL5/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YA6UNQSOY6M3NJDZLS6YJXTS4WGDMEEJ/ | Mailing List Third Party Advisory |
Information
Published : 2021-06-10 04:15
Updated : 2022-03-25 11:54
NVD link : CVE-2021-34363
Mitre link : CVE-2021-34363
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
the_fuck_project
- the_fuck
fedoraproject
- fedora