{"id":"GHSA-7488-6x3r-23w5","summary":"Ganga allows absolute path traversal","details":"The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask `send_file` function is used unsafely.","aliases":["CVE-2022-31507","PYSEC-2022-225"],"modified":"2025-02-21T05:31:10.336541Z","published":"2022-07-13T15:43:03Z","database_specific":{"nvd_published_at":"2022-07-11T01:15:00Z","cwe_ids":["CWE-22"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-07-13T15:43:03Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31507"},{"type":"WEB","url":"https://github.com/github/securitylab/issues/669#issuecomment-1117265726"},{"type":"WEB","url":"https://github.com/ganga-devs/ganga/commit/730e7aba192407d35eb37dd7938d49071124be8c"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7488-6x3r-23w5"},{"type":"PACKAGE","url":"https://github.com/ganga-devs/ganga"},{"type":"WEB","url":"https://github.com/ganga-devs/ganga/releases/tag/8.5.10"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ganga/PYSEC-2022-225.yaml"}],"affected":[{"package":{"name":"ganga","ecosystem":"PyPI","purl":"pkg:pypi/ganga"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.5.10"}]}],"versions":["6.1.15","6.1.16","6.1.17","6.1.18","6.1.19","6.1.20","6.1.21","6.1.22","6.1.23","6.1.24","6.1.25","6.2.0","6.2.1","6.2.2","6.2.3","6.3.0","6.3.1","6.4.0","6.5.0","6.5.1","6.5.2","6.6.0","6.6.1","6.6.2","6.6.3","6.6.4","6.7.0","6.7.1","6.7.2","6.7.3","6.7.4","7.0.0","7.0.1","7.0.2","7.0.3","7.0.4","7.1.0","7.1.1","7.1.10","7.1.11","7.1.12","7.1.13","7.1.14","7.1.15","7.1.3","7.1.4","7.1.5","7.1.6","7.1.7","7.1.8","7.1.9","8.0.0","8.0.1","8.0.2","8.0.3","8.1.0","8.2.0","8.2.1","8.2.2","8.2.3","8.2.4","8.3.0","8.3.1","8.3.2","8.3.3","8.3.4","8.3.4rc0","8.3.5","8.4.0","8.4.1","8.4.2","8.4.4","8.4.5","8.4.6","8.4.7","8.4.8","8.5.0","8.5.1","8.5.2","8.5.3","8.5.4","8.5.5","8.5.6","8.5.7","8.5.8","8.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-7488-6x3r-23w5/GHSA-7488-6x3r-23w5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L"}]}