{"id":"GHSA-qj8w-rv5x-2v9h","summary":"Duplicate Advisory: Starlette vulnerable to directory traversal","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-v5gw-mw7f-84px. This link is maintained to preserve external references.\n\n## Original Description\nDirectory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.","modified":"2025-02-18T06:19:36.795705Z","published":"2023-06-01T03:30:24Z","withdrawn":"2023-06-09T22:54:39Z","database_specific":{"nvd_published_at":"2023-06-01T02:15:09Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-06T02:01:03Z"},"references":[{"type":"WEB","url":"https://github.com/encode/starlette/security/advisories/GHSA-v5gw-mw7f-84px"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-29159"},{"type":"WEB","url":"https://github.com/encode/starlette/commit/1797de464124b090f10cf570441e8292936d63e3"},{"type":"PACKAGE","url":"https://github.com/encode/starlette"},{"type":"WEB","url":"https://github.com/encode/starlette/releases/tag/0.27.0"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN95981715"}],"affected":[{"package":{"name":"starlette","ecosystem":"PyPI","purl":"pkg:pypi/starlette"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.13.5"},{"fixed":"0.27.0"}]}],"versions":["0.13.5","0.13.6","0.13.7","0.13.8","0.14.0","0.14.1","0.14.2","0.15.0","0.16.0","0.17.0","0.17.1","0.18.0","0.19.0","0.19.1","0.20.0","0.20.1","0.20.2","0.20.3","0.20.4","0.21.0","0.22.0","0.23.0","0.23.1","0.24.0","0.25.0","0.26.0","0.26.0.post1","0.26.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-qj8w-rv5x-2v9h/GHSA-qj8w-rv5x-2v9h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}