PyPi: Falocalrepo

CVE-2022-30595

Transitive

Safety vulnerability ID: 59842

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at May 25, 2022 Updated at Oct 13, 2023
Scan your Python projects for vulnerabilities →

Advisory

Falocalrepo 4.3.1 updates its dependency 'falocalrepo-server' to version '3.2.2' to include a fix for a vulnerability.
https://github.com/FurryCoders/FALocalRepo/commit/807d2e9e47dcb3ec5cf21569025b9053e2b958b3

Affected package

falocalrepo

Latest version: 4.4.7

Pure Python program to download any user's gallery, scraps, favorites, and journals from FurAffinity in an easily handled database.

Affected versions

Fixed versions

Vulnerability changelog

New Features

* Open browser for server 💻
* A new browser tab/window is opened automatically when using the `server` command
* New `--browser` and `--no-browser` options for `server` to toggle opening the browser (defaults on)

Changes

* Requests are timed out after 60 seconds to avoid infinite waits during file downloads.

Dependencies

* falocalrepo-database dependency set to [\~5.3.4](https://pypi.org/project/falocalrepo-database/5.3.4)
* Fix incorrect extension selection for files with non-specific MIME types (e.g. docx)
* Interrupting a database backup does not leave a temporary file behind
* falocalrepo-server dependency set to [\~3.2.2](https://pypi.org/project/falocalrepo-server/3.2.2)
* Open browser on startup
* Fix [CVE-2022-30595](https://github.com/advisories/GHSA-hr8g-f6r6-mr22)
* Fix journals searches
* Fix visual errors
* Support spoiler text
* Add file counter in search results for submissions with multiple files
* faapi dependency set to [\~3.7.2](https://pypi.org/project/faapi/3.7.2)
* Fix journals parsing when using full date format
* Add requests timeout

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH

CVSS v2 Details

HIGH 7.5
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL