GHSA-vpqp-hx68-p2wx

    Dashboard / Vulnerabilities / GHSA-vpqp-hx68-p2wx

    GHSA-vpqp-hx68-p2wx

    Published: 14 May 2022Last Modified: 28 Oct 2024

    Summary: Improper Link Resolution Before File Access in Suds

    Details: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

    Affected packages

    Package

    Name: suds

    Purl: pkg:pypi/suds

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.0

    Affected versions

    0.3.4
    0.3.5
    0.3.6
    0.3.7
    0.3.8
    0.3.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High