Improper Output Neutralization for Logs Affecting streamlit package, versions [,1.27.0)
Threat Intelligence
Exploit Maturity
Proof of concept
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-STREAMLIT-5880413
- published 3 Sep 2023
- disclosed 2 Sep 2023
- credit 450ryousuke
How to fix?
Upgrade streamlit
to version 1.27.0 or higher.
Overview
streamlit is a The fastest way to build data apps in Python
Affected versions of this package are vulnerable to Improper Output Neutralization for Logs when the function upload_file_request_handler.py
returns 400 error including the session_id
value.
References
CVSS Scores
version 3.1