CVE-2022-35920
01.08.2022, 22:15
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrade. There is no known workaround for this issue.
Vendor | Product | Version |
---|---|---|
sanic_project | sanic | 𝑥 < 20.12.7 |
sanic_project | sanic | 21.0.0 ≤ 𝑥 < 21.12.2 |
sanic_project | sanic | 22.0.0 ≤ 𝑥 < 22.6.1 |
𝑥
= Vulnerable software versions
References