GHSA-wxmr-7xjv-8xqw
Dashboard / Vulnerabilities / GHSA-wxmr-7xjv-8xqw
GHSA-wxmr-7xjv-8xqw
Summary: django-markupfield Arbitrary File Read
Details: django-markupfield before 1.3.2 uses the default docutils `RESTRUCTUREDTEXT_FILTER_SETTINGS` settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-0846, https://github.com/jamesturk/django-markupfield/commit/b45734ea1d206abc1ed2a90bdc779708066d49f3, https://github.com/jamesturk/django-markupfield, https://github.com/jamesturk/django-markupfield/blob/1.3.3/CHANGELOG, https://github.com/jamesturk/django-markupfield/blob/master/CHANGELOG, https://github.com/pypa/advisory-database/tree/main/vulns/django-markupfield/PYSEC-2015-12.yaml, https://www.djangoproject.com/weblog/2015/apr/21/docutils-security-advisory, http://www.debian.org/security/2015/dsa-3230
Affected packages
Package
Name: django-markupfield
Purl: pkg:pypi/django-markupfield
Affected ranges
Type: ECOSYSTEM
Events:
