Improper Limitation of a Pathname to a Restricted Directory in sanic
CVE-2022-35920

8.3HIGH

Key Information:

Vendor

Sanic-org

Status
Vendor
CVE Published:
1 August 2022

What is CVE-2022-35920?

Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using app.static if using encoded %2F URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.

Affected Version(s)

sanic >= 22.0.0, < 22.6.1 < 22.0.0, 22.6.1

sanic >= 21.0.0, < 21.12.2 < 21.0.0, 21.12.2

sanic < 20.12.7 < 20.12.7

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.