PyPI package
bikeshed
pkg:pypi/bikeshed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-23422 | — | < 3.0.0 | 3.0.0 | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output. | ||
| CVE-2021-23423 | — | < 3.0.0 | 3.0.0 | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output. |
- CVE-2021-23422Aug 16, 2021affected < 3.0.0fixed 3.0.0
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Command metadata is processed. When an arbitrary OS command is executed, the command output would be included in the HTML output.
- CVE-2021-23423Aug 16, 2021affected < 3.0.0fixed 3.0.0
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include-code or include-raw block is processed. The contents of arbitrary files could be disclosed in the HTML output.