Skip to content

Minor fix to previous patch for CVE-2022-35918

Low severity GitHub Reviewed Published Jan 11, 2024 in streamlit/streamlit • Updated Jan 12, 2024

Package

pip streamlit (pip)

Affected versions

>= 0.63.0, < 1.30.0

Patched versions

1.30.0

Description

Impact

The initial vulnerability identified in Streamlit apps using custom components, allowing for directory traversal attacks, was addressed in version 1.11.1. However, a minor issue persisted, which could still potentially expose certain files on the server file-system under specific conditions.

Patches

We released an update in version 1.30.0 to further tighten security measures. Users are strongly advised to update to version 1.30.0 immediately for optimal security.

Workarounds

No additional workarounds are necessary once the update to version 1.30.0 is applied.

For more information

If you have any questions or comments about this advisory:

References

@sfc-gh-kmcgrady sfc-gh-kmcgrady published to streamlit/streamlit Jan 11, 2024
Published to the GitHub Advisory Database Jan 12, 2024
Reviewed Jan 12, 2024
Last updated Jan 12, 2024

Severity

Low

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-8qw9-gf7w-42x5

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.