Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-55077 | Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not validate the user-controlled filename variable and uses it in the send_file function, which leads to an arbitrary file read on the system. This issue is fixed in version 1.3.1. |
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-07T15:29:04.636Z
Reserved: 2023-12-05T20:42:59.379Z
Link: CVE-2023-50265
Updated: 2024-08-02T22:16:46.301Z
Status : Modified
Published: 2023-12-15T21:15:08.943
Modified: 2024-11-21T08:36:46.850
Link: CVE-2023-50265
No data.
OpenCVE Enrichment
No data.
EUVD