Debian Security Advisory 1481-1 - It was discovered that a directory traversal vulnerability in CherryPy, a pythonic, object-oriented web development framework may lead to denial of service by deleting files through malicious session IDs in cookies.
2d5292a88121aef527bffd7b0ee0ec142d4f5920d873bdf8bb0b39d09f0df0f6
Gentoo Linux Security Advisory GLSA 200801-11 - CherryPy does not sanitize the session id, provided as a cookie value, in the FileSession._get_file_path() function before using it as part of the file name. Versions less than 3.0.2-r1 are affected.
daf8abfdb93d6cff9bf00703877e00659ab26e1d72bb605e9a1f33ad266604c9