PyPI: streamlit
CVE-2022-35918
Safety vulnerability ID: SFTY-20220801-80951
Safety legacy ID: pyup.io-50437
In Streamlit affected versions, users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world-readable files, and potentially other sensitive information. An attacker can craft a malicious URL with file paths and the streamlit server would process that URL and return the contents of that file. This issue has been resolved in version 1.11.1. Users are advised to upgrade. There are no known workarounds for this issue.
Overview
Streamlit directory traversal vulnerability
Advisory
In Streamlit affected versions, users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world-readable files, and potentially other sensitive information. An attacker can craft a malicious URL with file paths and the streamlit server would process that URL and return the contents of that file. This issue has been resolved in version 1.11.1. Users are advised to upgrade. There are no known workarounds for this issue.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20220801-80951/CVE-2022-35918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-35918
- https://github.com/streamlit/streamlit/commit/80d9979d5f4a00217743d607078a1d867fad8acf
- https://github.com/streamlit/streamlit/security/advisories/GHSA-v4hr-4jpx-56gc
- https://github.com/streamlit/streamlit/security/advisories/GHSA-v4hr-4jpx-56gc
- https://nvd.nist.gov/vuln/detail/CVE-2022-35918
- https://github.com/streamlit/streamlit/commit/80d9979d5f4a00217743d607078a1d867fad8acf
- https://github.com/pypa/advisory-database/tree/main/vulns/streamlit/PYSEC-2022-248.yaml
- https://github.com/advisories/GHSA-v4hr-4jpx-56gc
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
