Insecure File Permissions Affecting dplib-py package, versions [,1.1.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-DPLIBPY-8145484
- published 2 Oct 2024
- disclosed 1 Oct 2024
- credit Unknown
How to fix?
Upgrade dplib-py
to version 1.1.0 or higher.
Overview
dplib-py is a Python implementation of the Data Package standard
Affected versions of this package are vulnerable to Insecure File Permissions allowing attackers to access files outside intended directories or gain unauthorized access to sensitive files.
Workaround
If updating isn't possible, carefully review and sanitize all inputs to path and file operations.