Executive brief
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.
Affected products
- PyPI sanic
Junglewise Threat Intelligence
CVE-2017-16762 · Severity: low · CVSS 3 · Published 2017-11-10
Technologies: sanic (PyPI). Vendors: PyPI.
Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.