Package | Installed | Affected | Info |
---|---|---|---|
pip | 19.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 19.3.1 | <21.1 |
show A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. |
pip | 19.3.1 | <21.1 |
show An issue was discovered in Pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). A warning was added about this behavior in version 21.1. NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely. |
pip | 19.3.1 | <21.1 |
show Pip 21.1 updates its dependency 'urllib3' to v1.26.4 due to security issues. |
pip | 19.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
bokeh | 1.4.0 | <2.4.2 |
show Bokeh 2.4.2 updates its dependency 'jquery-ui' to v1.13.0 to include security fixes. |
bokeh | 1.4.0 | <2.4.2 |
show Bokeh 2.4.2 updates its dependency 'jquery-ui' to v1.13.0 to include security fixes. |
bokeh | 1.4.0 | <2.4.2 |
show Bokeh 2.4.2 updates its dependency 'jquery-ui' to v1.13.0 to include security fixes. |
numpy | 1.22.0 | <1.22.2 |
show Numpy 1.22.2 includes a fix for CVE-2021-41495: Null Pointer Dereference vulnerability exists in numpy.sort in NumPy in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. NOTE: While correct that validation is missing, an error can only occur due to an exhaustion of memory. If the user can exhaust memory, they are already privileged. Further, it should be practically impossible to construct an attack which can target the memory exhaustion to occur at exactly this place. NOTE2: The specs we include in this advisory differ from the publicly available on other sources. For example, the advisory posted by the NVD indicate that versions up to and including 1.19.0 are affected. However, research by Safety CLI Cybersecurity confirms that the vulnerability remained unaddressed until version 1.22.2. |
plotly | 4.5.1 | <4.8.2 |
show Plotly 4.8.2 includes plotly.js version 1.54.5, which contains a security fix of a transitive dependency (ecstatic). |
plotly | 4.5.1 | <4.9.0 |
show Plotly 4.9.0 builds Javascript extensions using Node 12 with an updated 'package-lock.json' that has many fewer security warnings. |
pytest-runner | 5.2 | >0 |
show Pytest-runner depends on deprecated features of setuptools and relies on features that break security mechanisms in pip. For example ‘setup_requires’ and ‘tests_require’ bypass pip --require-hashes. See also pypa/setuptools#1684. It is recommended that you: - Remove 'pytest-runner' from your setup_requires, preferably removing the setup_requires option. - Remove 'pytest' and any other testing requirements from tests_require, preferably removing the tests_requires option. - Select a tool to bootstrap and then run tests such as tox. https://github.com/pytest-dev/pytest-runner/blob/289a77b179535d8137118e3b8591d9e727130d6d/README.rst |
Package | Installed | Affected | Info |
---|---|---|---|
Sphinx | 2.2.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Sphinx | 2.2.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in inventory. https://github.com/sphinx-doc/sphinx/issues/8175 https://github.com/sphinx-doc/sphinx/commit/f7b872e673f9b359a61fd287a7338a28077840d2 |
Sphinx | 2.2.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in docstring. https://github.com/sphinx-doc/sphinx/issues/8172 https://github.com/sphinx-doc/sphinx/commit/f00e75278c5999f40b214d8934357fbf0e705417 |
Sphinx | 2.2.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Package | Installed | Affected | Info |
---|---|---|---|
Sphinx | 2.2.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Sphinx | 2.2.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in inventory. https://github.com/sphinx-doc/sphinx/issues/8175 https://github.com/sphinx-doc/sphinx/commit/f7b872e673f9b359a61fd287a7338a28077840d2 |
Sphinx | 2.2.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in docstring. https://github.com/sphinx-doc/sphinx/issues/8172 https://github.com/sphinx-doc/sphinx/commit/f00e75278c5999f40b214d8934357fbf0e705417 |
Sphinx | 2.2.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
Package | Installed | Affected | Info |
---|
https://pyup.io/repos/github/andrewm4894/am4894plots/python-3-shield.svg
[](https://pyup.io/repos/github/andrewm4894/am4894plots/)
.. image:: https://pyup.io/repos/github/andrewm4894/am4894plots/python-3-shield.svg :target: https://pyup.io/repos/github/andrewm4894/am4894plots/ :alt: Python 3
<a href="https://pyup.io/repos/github/andrewm4894/am4894plots/"><img src="https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/andrewm4894/am4894plots/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/andrewm4894/am4894plots/
{<img src="https://pyup.io/repos/github/andrewm4894/am4894plots/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/andrewm4894/am4894plots/]
https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg
[](https://pyup.io/repos/github/andrewm4894/am4894plots/)
.. image:: https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg :target: https://pyup.io/repos/github/andrewm4894/am4894plots/ :alt: Updates
<a href="https://pyup.io/repos/github/andrewm4894/am4894plots/"><img src="https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg(Updates)!:https://pyup.io/repos/github/andrewm4894/am4894plots/
{<img src="https://pyup.io/repos/github/andrewm4894/am4894plots/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/andrewm4894/am4894plots/]