{"id":"GHSA-h454-rq3m-89rc","summary":"Wagtail CRX CodeRed Extensions vulnerable to Path Traversal","details":"views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.","aliases":["CVE-2021-46897","PYSEC-2023-210"],"modified":"2023-11-09T05:32:14.192946Z","published":"2023-10-22T21:36:10Z","database_specific":{"nvd_published_at":"2023-10-22T19:15:08Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-10-24T01:45:47Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-46897"},{"type":"WEB","url":"https://github.com/coderedcorp/coderedcms/issues/448"},{"type":"WEB","url":"https://github.com/coderedcorp/coderedcms/pull/450"},{"type":"WEB","url":"https://github.com/coderedcorp/coderedcms/commit/06006cec23a723bc7d76df75ce2c2d795a447902"},{"type":"PACKAGE","url":"https://github.com/coderedcorp/coderedcms"},{"type":"WEB","url":"https://github.com/coderedcorp/coderedcms/compare/v0.22.2...v0.22.3"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/coderedcms/PYSEC-2023-210.yaml"}],"affected":[{"package":{"name":"coderedcms","ecosystem":"PyPI","purl":"pkg:pypi/coderedcms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.22.3"}]}],"versions":["0.10.0","0.11.0","0.12.0","0.12.1","0.13.0","0.13.1","0.13.2","0.13.3","0.14.0","0.14.1","0.15.0","0.15.1","0.15.2","0.16.0","0.16.1","0.16.2","0.16.3","0.17.0","0.18.0","0.18.1","0.18.2","0.19.0","0.19.0rc1","0.19.1","0.20.0","0.21.0","0.21.1","0.22.0","0.22.1","0.22.2","0.5.0","0.5.1","0.6.0","0.7.0","0.7.1","0.8.0","0.9.0","0.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-h454-rq3m-89rc/GHSA-h454-rq3m-89rc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}