GHSA-x2pc-fqrw-hc7f
CRITICALCVE-2022-31506The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask sendfile function is used unsafely. A patch is available on the master branch of the repository.
- Affected
- <= 10.1.1
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2022-07-12
- Source
- github