{"id":"GHSA-c8f7-x2g7-7fxj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c8f7-x2g7-7fxj","summary":"Phoenix-ws source code and data in extensions folder is publicly available","details":"### Impact\nAll of the source code, files, and folders in `phoenix_files/extensions/` are available to end users through a simple HTTP GET request.\n\n### Patches\nThe issue has been patched. The users of version 1.0.6 and above are not effected.","published":"2022-06-02T14:23:29Z","modified":"2024-12-03T06:03:05.663847Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"phoenix-ws","fixedVersion":"1.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Froggo8311/Phoenix/security/advisories/GHSA-c8f7-x2g7-7fxj"},{"type":"PACKAGE","url":"https://github.com/Froggo8311/Phoenix"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-03T06:03:05.663847Z"}}