Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
1.1.3+ds1-2ubuntu0.21.3.2-1ubuntu0.11.3.9-1ubuntu0.11.3.10-3ubuntu0.11.0.3+ds1-1ubuntu1+esm21.0.7+ds1-1ubuntu0.2+esm11.1.0+ds1-1ubuntu2.1+esm1Exploitability
AV:NAC:LAT:NPR:NUI:NVulnerable System
VC:HVI:NVA:NSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P