cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| suds(PyPI) | 0 | 1.0.0 | N/A |
| suds-py3(PyPI) | 0 | 1.4.4.1 | N/A |
CVSS Metrics