570
VMScore

CVE-2021-34363

Published: 10/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The thefuck (aka The Fuck) package prior to 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

the fuck project the fuck

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #989989 CVE-2021-34363 Package: thefuck; Maintainer for thefuck is Alessio Treglia <alessio@debianorg>; Source for thefuck is src:thefuck (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 17 Jun 2021 13:18:04 UTC Severity: important Tags: security, upstream ...
The thefuck package before 331 allows path traversal that leads to arbitrary file deletion via the "undo archive operation" feature ...