{"id":"GHSA-hf6p-4rv2-9qrp","summary":"Path Traversal in bikshed","details":"This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.","aliases":["CVE-2021-23423","PYSEC-2021-117","SNYK-PYTHON-BIKESHED-1537647"],"modified":"2024-09-04T21:21:13.616102Z","published":"2021-08-30T16:25:42Z","database_specific":{"github_reviewed_at":"2021-08-26T15:45:24Z","nvd_published_at":"2021-08-16T08:15:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23423"},{"type":"WEB","url":"https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cb6b2dd"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/bikeshed/PYSEC-2021-117.yaml"},{"type":"PACKAGE","url":"https://github.com/tabatkins/bikeshed"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537647"}],"affected":[{"package":{"name":"bikeshed","ecosystem":"PyPI","purl":"pkg:pypi/bikeshed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.0"}]}],"versions":["1.0.0","1.0.1","1.0.10","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.2.0","1.2.1","1.2.2","1.3.0","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.5.3","1.6.0","1.6.1","1.6.2","1.6.3","1.7.0","2.0.0","2.1.0","2.2.0","2.2.1","2.2.2","2.2.3","2.3.0","2.3.1","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.4.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-hf6p-4rv2-9qrp/GHSA-hf6p-4rv2-9qrp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}