PyPi: Gns3-Gui

CVE-2019-18874

Transitive

Safety vulnerability ID: 58989

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Nov 12, 2019 Updated at May 15, 2024
Scan your Python projects for vulnerabilities →

Advisory

Gns3-gui 2.2.6 updates its dependency 'psutil' to version '5.6.6' to include a security fix.
https://github.com/GNS3/gns3-gui/commit/ab15f96bb57e27689298f1912f6ce87195bff0a5
https://github.com/advisories/GHSA-qfc5-mcwq-26q8

Affected package

gns3-gui

Latest version: 2.2.47

GNS3 graphical interface for the GNS3 server.

Affected versions

Fixed versions

Vulnerability changelog

* Prevent locked drawings to be deleted. Fixes https://github.com/GNS3/gns3-gui/issues/2948
* Fix issues with empty project variables. Fixes https://github.com/GNS3/gns3-gui/issues/2941
* Upgrade psutil to version 5.6.6 due to CVE-2019-18874 https://github.com/advisories/GHSA-qfc5-mcwq-26q8
* Use existing README.txt if existing when exporting portable project. Fixes https://github.com/GNS3/gns3-server/issues/1724
* Allow creation of a diskless Qemu VMs. Fixes 2939
* Re-enable "create new version" in appliance wizard. Fixes 2837
* Fix unable to load project from project library. Fixes 2932
* Fix some permission denied errors when loading remote project. Ref 2871 Fixes 2901
* Add 'Royal TS V5' to predefined console list
* Disallow invalid grid sized. Fixes 2908
* Check if hostname is blank. Fixes 2924
* Add nvme disk interface and fix scsi disk interface for Qemu VMs.
* Add latest Qemu nic models.
* Upgrade Qt version to 5.14.1. Ref 2778 2903

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
HIGH

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Impact (A)
PARTIAL