CVE-2023-29159Path Traversal in Starlette

CWE-22Path Traversal5 documents4 sources
Severity
7.5HIGHNVD
EPSS
1.5%
top 18.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1

Description

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDencode/starlette0.13.50.27.0
PyPIencode/starlette0.13.50.27.0
debiandebian/starlette< starlette 0.28.0-1 (forky)
Debianencode/starlette< 0.28.0-1+1
CVEListV5encode/starletteversions 0.13.5 and later and prior to 0.27.0

🔴Vulnerability Details

3
OSV
CVE-2023-29159: Directory traversal vulnerability in Starlette versions 02023-06-01
OSV
Starlette has Path Traversal vulnerability in StaticFiles2023-05-17
GHSA
Starlette has Path Traversal vulnerability in StaticFiles2023-05-17

📋Vendor Advisories

1
Debian
CVE-2023-29159: starlette - Directory traversal vulnerability in Starlette versions 0.13.5 and later and pri...2023