{"id":"PYSEC-2019-213","details":"The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.","aliases":["CVE-2019-17400","GHSA-27p5-7cw6-m45h"],"modified":"2023-11-08T04:01:23.639213Z","published":"2019-10-21T23:15:00Z","references":[{"type":"WEB","url":"https://github.com/unoconv/unoconv/pull/510"},{"type":"WEB","url":"https://buer.haus/2019/10/18/a-tale-of-exploitation-in-spreadsheet-file-conversions/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-27p5-7cw6-m45h"}],"affected":[{"package":{"name":"unoconv","ecosystem":"PyPI","purl":"pkg:pypi/unoconv"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0"}]}],"versions":["0.6","0.8.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/unoconv/PYSEC-2019-213.yaml"}}],"schema_version":"1.7.3"}