GHSA-r9x7-2xmr-v8fw

    Dashboard / Vulnerabilities / GHSA-r9x7-2xmr-v8fw

    GHSA-r9x7-2xmr-v8fw

    Published: 16 Sept 2022Last Modified: 30 Sept 2024

    Summary: mangadex-downloader vulnerable to unauthorized file reading

    Details: ### Impact When using `file:<location>` command and `<location>` is web URL location (http, https). mangadex-downloader will try to open and read a file in local disk if the content from online file is exist-as-a-file in victim computer So far, the app only read the files and not execute it. But still, when someone reading your files without you knowing, it's very scary. ### Proof of Concept (PoC) https://www.mansuf.link/unauthorized-file-read-in-mangadex-downloader-cve-2022-36082/ ### Workarounds Unfortunately, there is no workarounds to make it safe from this issue. But i suggest you double check the url before proceed to download or update to latest version ( >= 1.7.2) ### Patches Fixed in version 1.7.2. Commit patch: https://github.com/mansuf/mangadex-downloader/commit/439cc2825198ebc12b3310c95c39a8c7710c9b42

    Affected packages

    Package

    Name: mangadex-downloader

    Purl: pkg:pypi/mangadex-downloader

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.3.0
    Fixed -1.7.2

    Affected versions

    1.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r9x7-2xmr-v8fw | CVE-DB