Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/python-poetry/poetry-core/pull/205/commits/fa9cb6f358ae840885c700f954317f34838caba7 | Patch Third Party Advisory | 
| https://github.com/python-poetry/poetry/releases/tag/1.1.9 | Release Notes Third Party Advisory | 
| https://www.sonarsource.com/blog/securing-developer-tools-package-managers/ | |
| https://github.com/python-poetry/poetry-core/pull/205/commits/fa9cb6f358ae840885c700f954317f34838caba7 | Patch Third Party Advisory | 
| https://github.com/python-poetry/poetry/releases/tag/1.1.9 | Release Notes Third Party Advisory | 
| https://www.sonarsource.com/blog/securing-developer-tools-package-managers/ | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 06:53
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/python-poetry/poetry-core/pull/205/commits/fa9cb6f358ae840885c700f954317f34838caba7 - Patch, Third Party Advisory | |
| References | () https://github.com/python-poetry/poetry/releases/tag/1.1.9 - Release Notes, Third Party Advisory | |
| References | () https://www.sonarsource.com/blog/securing-developer-tools-package-managers/ - | 
29 Mar 2022, 14:56
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://github.com/python-poetry/poetry/releases/tag/1.1.9 - Release Notes, Third Party Advisory | |
| References | (MISC) https://github.com/python-poetry/poetry-core/pull/205/commits/fa9cb6f358ae840885c700f954317f34838caba7 - Patch, Third Party Advisory | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 7.5
         v3 : 9.8  | 
| CWE | CWE-426 | |
| CPE | cpe:2.3:a:python-poetry:poetry:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*  | 
21 Mar 2022, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-03-21 22:15
Updated : 2024-11-21 06:53
NVD link : CVE-2022-26184
Mitre link : CVE-2022-26184
CVE.ORG link : CVE-2022-26184
JSON object : View
Products Affected
                python-poetry
- poetry
 
microsoft
- windows
 
CWE
                
                    
                        
                        CWE-426
                        
            Untrusted Search Path
