CVE-2020-15141

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
14/08/2020
Last modified:
20/08/2020

Description

In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openapi-python-client_project:openapi-python-client:*:*:*:*:*:*:*:* 0.5.3 (excluding)