Package | Installed | Affected | Info |
---|---|---|---|
Sphinx | 1.7.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Sphinx | 1.7.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in inventory. https://github.com/sphinx-doc/sphinx/issues/8175 https://github.com/sphinx-doc/sphinx/commit/f7b872e673f9b359a61fd287a7338a28077840d2 |
Sphinx | 1.7.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in docstring. https://github.com/sphinx-doc/sphinx/issues/8172 https://github.com/sphinx-doc/sphinx/commit/f00e75278c5999f40b214d8934357fbf0e705417 |
Sphinx | 1.7.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
pycryptodome | 3.4.11 | <3.10.3 |
show Pycryptodome 3.10.3 improves robustness of PKCS1v1.5 decryption against timing attacks. https://github.com/Legrandin/pycryptodome/commit/853054937e29e6cd3dc61228be1dc768b688460b |
pycryptodome | 3.4.11 | <3.6.6 |
show Pycryptodome before 3.6.6 has a vulnerability on AESNI ECB with payloads smaller than 16 bytes. |
pycryptodome | 3.4.11 | <3.11.0 |
show Pycryptodome version 3.11.0 includes a fix for the DSA construction algorithm. Modulus "p" primality check wasn't working. https://github.com/Legrandin/pycryptodome/pull/557/commits/183f8d1c7a5e145e78b86fb54da7e327a277d9c6 |
pycryptodome | 3.4.11 | <3.20.0 |
show Pycryptodome 3.20.0 addresses a vulnerability in the OAEP decryption process, which previously had a side-channel leakage issue. This vulnerability could potentially be exploited through a Manger attack, a type of cryptographic attack. The resolution of this issue enhances the security of the library, especially in its handling of OAEP decryption. https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd |
pycryptodome | 3.4.11 | >=0,<3.19.1 |
show PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 19.2 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 19.2 | <21.1 |
show A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. |
pip | 19.2 | <21.1 |
show Pip 21.1 updates its dependency 'urllib3' to v1.26.4 due to security issues. |
pip | 19.2 | <21.1 |
show An issue was discovered in Pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). A warning was added about this behavior in version 21.1. NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely. |
pip | 19.2 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Sphinx | 1.7.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
Sphinx | 1.7.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in inventory. https://github.com/sphinx-doc/sphinx/issues/8175 https://github.com/sphinx-doc/sphinx/commit/f7b872e673f9b359a61fd287a7338a28077840d2 |
Sphinx | 1.7.1 | <3.3.0 |
show Sphinx 3.3.0 includes a fix for a ReDoS vulnerability in docstring. https://github.com/sphinx-doc/sphinx/issues/8172 https://github.com/sphinx-doc/sphinx/commit/f00e75278c5999f40b214d8934357fbf0e705417 |
Sphinx | 1.7.1 | <3.0.4 |
show Sphinx 3.0.4 updates jQuery version from 3.4.1 to 3.5.1 for security reasons. |
pycryptodome | 3.4.11 | <3.10.3 |
show Pycryptodome 3.10.3 improves robustness of PKCS1v1.5 decryption against timing attacks. https://github.com/Legrandin/pycryptodome/commit/853054937e29e6cd3dc61228be1dc768b688460b |
pycryptodome | 3.4.11 | <3.6.6 |
show Pycryptodome before 3.6.6 has a vulnerability on AESNI ECB with payloads smaller than 16 bytes. |
pycryptodome | 3.4.11 | <3.11.0 |
show Pycryptodome version 3.11.0 includes a fix for the DSA construction algorithm. Modulus "p" primality check wasn't working. https://github.com/Legrandin/pycryptodome/pull/557/commits/183f8d1c7a5e145e78b86fb54da7e327a277d9c6 |
pycryptodome | 3.4.11 | <3.20.0 |
show Pycryptodome 3.20.0 addresses a vulnerability in the OAEP decryption process, which previously had a side-channel leakage issue. This vulnerability could potentially be exploited through a Manger attack, a type of cryptographic attack. The resolution of this issue enhances the security of the library, especially in its handling of OAEP decryption. https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd |
pycryptodome | 3.4.11 | >=0,<3.19.1 |
show PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. |
Package | Installed | Affected | Info |
---|---|---|---|
pycryptodome | 3.4.11 | <3.10.3 |
show Pycryptodome 3.10.3 improves robustness of PKCS1v1.5 decryption against timing attacks. https://github.com/Legrandin/pycryptodome/commit/853054937e29e6cd3dc61228be1dc768b688460b |
pycryptodome | 3.4.11 | <3.6.6 |
show Pycryptodome before 3.6.6 has a vulnerability on AESNI ECB with payloads smaller than 16 bytes. |
pycryptodome | 3.4.11 | <3.11.0 |
show Pycryptodome version 3.11.0 includes a fix for the DSA construction algorithm. Modulus "p" primality check wasn't working. https://github.com/Legrandin/pycryptodome/pull/557/commits/183f8d1c7a5e145e78b86fb54da7e327a277d9c6 |
pycryptodome | 3.4.11 | <3.20.0 |
show Pycryptodome 3.20.0 addresses a vulnerability in the OAEP decryption process, which previously had a side-channel leakage issue. This vulnerability could potentially be exploited through a Manger attack, a type of cryptographic attack. The resolution of this issue enhances the security of the library, especially in its handling of OAEP decryption. https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd |
pycryptodome | 3.4.11 | >=0,<3.19.1 |
show PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. |
https://pyup.io/repos/github/koshikraj/justblockchain/python-3-shield.svg
[](https://pyup.io/repos/github/koshikraj/justblockchain/)
.. image:: https://pyup.io/repos/github/koshikraj/justblockchain/python-3-shield.svg :target: https://pyup.io/repos/github/koshikraj/justblockchain/ :alt: Python 3
<a href="https://pyup.io/repos/github/koshikraj/justblockchain/"><img src="https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/koshikraj/justblockchain/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/koshikraj/justblockchain/
{<img src="https://pyup.io/repos/github/koshikraj/justblockchain/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/koshikraj/justblockchain/]
https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg
[](https://pyup.io/repos/github/koshikraj/justblockchain/)
.. image:: https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg :target: https://pyup.io/repos/github/koshikraj/justblockchain/ :alt: Updates
<a href="https://pyup.io/repos/github/koshikraj/justblockchain/"><img src="https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg(Updates)!:https://pyup.io/repos/github/koshikraj/justblockchain/
{<img src="https://pyup.io/repos/github/koshikraj/justblockchain/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/koshikraj/justblockchain/]