Vulnerability Description
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bikeshed Project | Bikeshed | < 3.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cbPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537647ExploitPatchThird Party Advisory
- https://github.com/tabatkins/bikeshed/commit/b2f668fca204260b1cad28d5078e93471cbPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-PYTHON-BIKESHED-1537647ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-23423?
CVE-2021-23423 is a vulnerability with a CVSS score of 5.5 (MEDIUM). This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could b...
How severe is CVE-2021-23423?
CVE-2021-23423 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23423?
Check the references section above for vendor advisories and patch information. Affected products include: Bikeshed Project Bikeshed.