seffaflik@0.0.4 vulnerabilities

EPİAŞ tarafından Şeffaflık Platformunda yayımlanmakta olan verileri çekmek için tasarlanmış Python kütüphanesi

  • latest version

    0.0.22

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    3 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the seffaflik package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Incorrect Permission Assignment for Critical Resource

    seffaflik is an EPİAŞ tarafından Şeffaflık Platformunda yayımlanmakta olan verileri çekmek için tasarlanmış Python kütüphanesi

    Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the creation of .kimlik and .seffaflik files with overly permissive permissions and the absence of symlink checks when writing to .kimlik. An attacker can access sensitive information or overwrite arbitrary files by exploiting these insecure file operations.

    How to fix Incorrect Permission Assignment for Critical Resource?

    Upgrade seffaflik to version 0.0.9 or higher.

    [,0.0.9)