{"id":"PYSEC-2022-248","details":"Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files, and potentially other sensitive information. An attacker can craft a malicious URL with file paths and the streamlit server would process that URL and return the contents of that file or overwrite existing files on the web-server. This issue has been resolved in version 1.11.1. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["CVE-2022-35918","GHSA-v4hr-4jpx-56gc"],"modified":"2023-11-01T04:59:23.441100Z","published":"2022-08-01T22:15:00Z","references":[{"type":"ADVISORY","url":"https://github.com/streamlit/streamlit/security/advisories/GHSA-v4hr-4jpx-56gc"},{"type":"FIX","url":"https://github.com/streamlit/streamlit/commit/80d9979d5f4a00217743d607078a1d867fad8acf"}],"affected":[{"package":{"name":"streamlit","ecosystem":"PyPI","purl":"pkg:pypi/streamlit"},"ranges":[{"type":"GIT","repo":"https://github.com/streamlit/streamlit","events":[{"introduced":"0"},{"fixed":"80d9979d5f4a00217743d607078a1d867fad8acf"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0.63.0"},{"fixed":"1.11.1"}]}],"versions":["0.63.0","0.63.1","0.64.0","0.65.0","0.65.1","0.65.2","0.66.0","0.67.0","0.67.1","0.68.0","0.68.1","0.69.0","0.69.1","0.69.2","0.70.0","0.71.0","0.72.0","0.73.0","0.73.1","0.74.0","0.74.1","0.75.0","0.76.0","0.77.0","0.78.0","0.79.0","0.80.0","0.81.0","0.81.1","0.82.0","0.83.0","0.84.0","0.84.1","0.84.2","0.85.0","0.85.1","0.86.0","0.87.0","0.88.0","0.89.0","1.0.0","1.1.0","1.10.0","1.10.0rc1","1.10.0rc2","1.11.0","1.11.0rc1","1.11.1rc1","1.2.0","1.3.0","1.3.1","1.4.0","1.5.0","1.5.1","1.6.0","1.6.0rc3","1.6.0rc4","1.7.0","1.8.0","1.8.0rc1","1.8.1","1.8.1rc1","1.9.0","1.9.0rc1","1.9.1","1.9.1rc1","1.9.1rc2","1.9.2","1.9.2rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/streamlit/PYSEC-2022-248.yaml"}}],"schema_version":"1.7.3"}