PT-2024-40201 · Streamlit · Streamlit

Published

2024-01-12

·

Updated

2024-01-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Streamlit versions prior to 1.30.0 Streamlit versions prior to 1.11.1 are also affected, but the issue was partially addressed in version 1.11.1
Description: The issue allows for directory traversal attacks, potentially exposing certain files on the server file-system under specific conditions.
Recommendations: For versions prior to 1.11.1, update to version 1.11.1 to partially address the issue. For versions 1.11.1 through 1.29.x, update to version 1.30.0 immediately for optimal security.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-8QW9-GF7W-42X5

Affected Products

Streamlit