The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
References
Configurations
Information
Published : 2021-06-10 11:15
Updated : 2022-01-19 04:15
NVD link : CVE-2021-34363
Mitre link : CVE-2021-34363
JSON object : View
Products Affected
the_fuck_project
- the_fuck
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
