| Package | Installed | Affected | Info |
|---|---|---|---|
| wheel | 0.37.1 | <0.46.2 |
show Affected versions of the wheel package are vulnerable to Path Traversal due to applying extracted file permissions using an unsanitized archive pathname. The vulnerable logic is in wheel.cli.unpack.unpack (and setuptools._vendor.wheel.cli.unpack.unpack), where the code calls wf.extract(zinfo, destination) but then performs destination.joinpath(zinfo.filename).chmod(permissions) using zinfo.filename directly, allowing dot-dot-slash sequences to escape the intended directory. |
| wheel | 0.37.1 | <0.38.1 |
show Wheel 0.38.1 includes a fix for CVE-2022-40898: An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli. https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages |
| Package | Installed | Affected | Info |
|---|---|---|---|
| wheel | 0.37.1 | <0.46.2 |
show Affected versions of the wheel package are vulnerable to Path Traversal due to applying extracted file permissions using an unsanitized archive pathname. The vulnerable logic is in wheel.cli.unpack.unpack (and setuptools._vendor.wheel.cli.unpack.unpack), where the code calls wf.extract(zinfo, destination) but then performs destination.joinpath(zinfo.filename).chmod(permissions) using zinfo.filename directly, allowing dot-dot-slash sequences to escape the intended directory. |
| wheel | 0.37.1 | <0.38.1 |
show Wheel 0.38.1 includes a fix for CVE-2022-40898: An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli. https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages |
https://pyup.io/repos/github/glichtner/fsh-validator/python-3-shield.svg
[](https://pyup.io/repos/github/glichtner/fsh-validator/)
.. image:: https://pyup.io/repos/github/glichtner/fsh-validator/python-3-shield.svg
:target: https://pyup.io/repos/github/glichtner/fsh-validator/
:alt: Python 3
<a href="https://pyup.io/repos/github/glichtner/fsh-validator/"><img src="https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/glichtner/fsh-validator/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/glichtner/fsh-validator/
{<img src="https://pyup.io/repos/github/glichtner/fsh-validator/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/glichtner/fsh-validator/]
https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg
[](https://pyup.io/repos/github/glichtner/fsh-validator/)
.. image:: https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg
:target: https://pyup.io/repos/github/glichtner/fsh-validator/
:alt: Updates
<a href="https://pyup.io/repos/github/glichtner/fsh-validator/"><img src="https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg(Updates)!:https://pyup.io/repos/github/glichtner/fsh-validator/
{<img src="https://pyup.io/repos/github/glichtner/fsh-validator/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/glichtner/fsh-validator/]