CVE-2021-34363

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/06/2021
Last modified:
07/11/2023

Description

The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:the_fuck_project:the_fuck:*:*:*:*:*:python:*:* 3.31 (excluding)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*