An issue was discovered in Python 3.11 through 3.11.4. If...
High severity
Unreviewed
Published
Aug 23, 2023
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Aug 23, 2023
Published to the GitHub Advisory Database
Aug 23, 2023
Last updated
Nov 10, 2023
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
References