UBUNTU-CVE-2021-40978
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-40978
UBUNTU-CVE-2021-40978
Summary:
Details: ** DISPUTED ** The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1.
References: https://ubuntu.com/security/CVE-2021-40978, https://github.com/nisdn/CVE-2021-40978, https://github.com/mkdocs/mkdocs, https://github.com/mkdocs/mkdocs/pull/2604, https://github.com/mkdocs/mkdocs/pull/2604/commits/cddc453c9d49298e60e7d56fb71130c151cbcbe5, https://www.cve.org/CVERecord?id=CVE-2021-40978
Affected packages
Package
Name: python-mkdocs
Purl: pkg:deb/ubuntu/python-mkdocs
Affected ranges
Type: ECOSYSTEM
Events:
