Vulnerability Details CVE-2023-41105
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.2%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-41105
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:python:python:3.11.0
-
cpe:2.3:a:python:python:3.11.1
-
cpe:2.3:a:python:python:3.11.2
-
cpe:2.3:a:python:python:3.11.3
-
cpe:2.3:a:python:python:3.11.4