GMS-2024-20: Minor fix to previous patch for CVE-2022-35918
(updated )
The initial vulnerability identified in Streamlit apps using custom components, allowing for directory traversal attacks, was addressed in version 1.11.1. However, a minor issue persisted, which could still potentially expose certain files on the server file-system under specific conditions.
References
Code Behaviors & Features
Detect and mitigate GMS-2024-20 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →