Bugzilla – Bug 1211891
VUL-0: CVE-2023-29159: python-starlette: directory traversal vulnerability
Last modified: 2023-06-01 08:53:17 UTC
CVE-2023-29159 Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-29159 https://bugzilla.redhat.com/show_bug.cgi?id=2211584 https://www.cve.org/CVERecord?id=CVE-2023-29159 https://github.com/encode/starlette/releases/tag/0.27.0 https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84px https://jvn.jp/en/jp/JVN95981715/
We already ship a fixed version, closing.