| Package | Installed | Affected | Info |
|---|---|---|---|
| mako | 1.2.0 | <1.3.12 |
show Affected versions of the Mako package are vulnerable to Path Traversal due to a mismatch between the posixpath-based URI normalisation used in TemplateLookup.get_template() and the Windows-native ntpath path resolution used by os.path.isfile() and os.path.normpath() in Template.__init__(). The get_template() method normalises the URI using posixpath, which treats backslashes as literal characters and thus fails to detect directory traversal sequences embedded via backslash separators, while os.path.normpath() in Template.__init__() resolves backslash-based .. sequences to a form that bypasses the startswith("..") guard. An attacker who can supply a user-controlled template name or include path to TemplateLookup.get_template() on a Windows host can read arbitrary files outside the configured template directory, and if the targeted file contains Mako or Python template syntax, it may additionally be parsed and executed as a template. |
| mako | 1.2.0 | <=1.3.10 |
show Affected versions of the Mako package are vulnerable to Path Traversal due to inconsistent stripping of leading slashes between TemplateLookup.get_template() and Template.init when resolving a template URI. TemplateLookup.get_template() strips all leading forward slashes before joining the URI with the template directory via posixpath.join, while Template.init strips only a single leading slash before calling normpath, so a URI beginning with a double slash is resolved to an absolute path like /etc/passwd that bypasses the subsequent startswith traversal check. An attacker who can pass untrusted input to TemplateLookup.get_template() can exploit this to read arbitrary files readable by the process and have their contents returned as rendered template output, resulting in unauthorized arbitrary file disclosure. |
| mako | 1.2.0 | <1.2.2 |
show Mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages |
| Package | Installed | Affected | Info |
|---|---|---|---|
| mako | 1.2.0 | <1.3.12 |
show Affected versions of the Mako package are vulnerable to Path Traversal due to a mismatch between the posixpath-based URI normalisation used in TemplateLookup.get_template() and the Windows-native ntpath path resolution used by os.path.isfile() and os.path.normpath() in Template.__init__(). The get_template() method normalises the URI using posixpath, which treats backslashes as literal characters and thus fails to detect directory traversal sequences embedded via backslash separators, while os.path.normpath() in Template.__init__() resolves backslash-based .. sequences to a form that bypasses the startswith("..") guard. An attacker who can supply a user-controlled template name or include path to TemplateLookup.get_template() on a Windows host can read arbitrary files outside the configured template directory, and if the targeted file contains Mako or Python template syntax, it may additionally be parsed and executed as a template. |
| mako | 1.2.0 | <=1.3.10 |
show Affected versions of the Mako package are vulnerable to Path Traversal due to inconsistent stripping of leading slashes between TemplateLookup.get_template() and Template.init when resolving a template URI. TemplateLookup.get_template() strips all leading forward slashes before joining the URI with the template directory via posixpath.join, while Template.init strips only a single leading slash before calling normpath, so a URI beginning with a double slash is resolved to an absolute path like /etc/passwd that bypasses the subsequent startswith traversal check. An attacker who can pass untrusted input to TemplateLookup.get_template() can exploit this to read arbitrary files readable by the process and have their contents returned as rendered template output, resulting in unauthorized arbitrary file disclosure. |
| mako | 1.2.0 | <1.2.2 |
show Mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin. https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages |
https://pyup.io/repos/github/alphagov/notifications-api/python-3-shield.svg
[](https://pyup.io/repos/github/alphagov/notifications-api/)
.. image:: https://pyup.io/repos/github/alphagov/notifications-api/python-3-shield.svg
:target: https://pyup.io/repos/github/alphagov/notifications-api/
:alt: Python 3
<a href="https://pyup.io/repos/github/alphagov/notifications-api/"><img src="https://pyup.io/repos/github/alphagov/notifications-api/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/alphagov/notifications-api/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/alphagov/notifications-api/
{<img src="https://pyup.io/repos/github/alphagov/notifications-api/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/alphagov/notifications-api/]
https://pyup.io/repos/github/alphagov/notifications-api/shield.svg
[](https://pyup.io/repos/github/alphagov/notifications-api/)
.. image:: https://pyup.io/repos/github/alphagov/notifications-api/shield.svg
:target: https://pyup.io/repos/github/alphagov/notifications-api/
:alt: Updates
<a href="https://pyup.io/repos/github/alphagov/notifications-api/"><img src="https://pyup.io/repos/github/alphagov/notifications-api/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/alphagov/notifications-api/shield.svg(Updates)!:https://pyup.io/repos/github/alphagov/notifications-api/
{<img src="https://pyup.io/repos/github/alphagov/notifications-api/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/alphagov/notifications-api/]