| Package | Installed | Affected | Info |
|---|---|---|---|
| wheel | 0.40.0 | <0.46.2 |
show Affected versions of the wheel package are vulnerable to Path Traversal due to applying extracted file permissions using an unsanitized archive pathname. The vulnerable logic is in wheel.cli.unpack.unpack (and setuptools._vendor.wheel.cli.unpack.unpack), where the code calls wf.extract(zinfo, destination) but then performs destination.joinpath(zinfo.filename).chmod(permissions) using zinfo.filename directly, allowing dot-dot-slash sequences to escape the intended directory. |
https://pyup.io/repos/github/rnag/wystia/python-3-shield.svg
[](https://pyup.io/repos/github/rnag/wystia/)
.. image:: https://pyup.io/repos/github/rnag/wystia/python-3-shield.svg
:target: https://pyup.io/repos/github/rnag/wystia/
:alt: Python 3
<a href="https://pyup.io/repos/github/rnag/wystia/"><img src="https://pyup.io/repos/github/rnag/wystia/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/rnag/wystia/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/rnag/wystia/
{<img src="https://pyup.io/repos/github/rnag/wystia/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/rnag/wystia/]
https://pyup.io/repos/github/rnag/wystia/shield.svg
[](https://pyup.io/repos/github/rnag/wystia/)
.. image:: https://pyup.io/repos/github/rnag/wystia/shield.svg
:target: https://pyup.io/repos/github/rnag/wystia/
:alt: Updates
<a href="https://pyup.io/repos/github/rnag/wystia/"><img src="https://pyup.io/repos/github/rnag/wystia/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/rnag/wystia/shield.svg(Updates)!:https://pyup.io/repos/github/rnag/wystia/
{<img src="https://pyup.io/repos/github/rnag/wystia/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/rnag/wystia/]