Junglewise Threat Intelligence

PYSEC-2023-297 - A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting

Severity: low · CVSS 3.1 · Published 2023-12-13

Technologies: repox (PyPI). Vendors: PyPI.

Executive brief

A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting in a disclosure of sensitive information. An attacker could access files such as application code or data, backend credentials, operating system files...

Affected products

  • PyPI repox

Related threats