1
0
mirror of https://github.com/pyenv/pyenv.git synced 2025-11-14 06:13:53 -05:00

CVE-2022-35861: Fixed relative path traversal due to using version string in path (#2412)

This commit is contained in:
James Stronz
2022-07-16 15:01:04 -07:00
committed by GitHub
parent 0eba0a5bd5
commit 22fa683571
2 changed files with 22 additions and 3 deletions

View File

@@ -82,3 +82,15 @@ IN
run pyenv-version-file-read my-version
assert_success "3.9.3:3.8.9:2.7.16"
}
@test "skips relative path traversal" {
cat > my-version <<IN
3.9.3
3.8.9
..
./*
2.7.16
IN
run pyenv-version-file-read my-version
assert_success "3.9.3:3.8.9:2.7.16"
}