PyPi: Pysteps

CVE-2020-10735

Transitive

Safety vulnerability ID: 45285

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 09, 2022 Updated at Apr 24, 2024
Scan your Python projects for vulnerabilities →

Advisory

Pysteps 1.6.0 drops support for Python 3.6 as it arrived to end-of-life and don't receive security updates anymore.

Affected package

pysteps

Latest version: 1.9.0

Python framework for short-term ensemble prediction systems

Affected versions

Fixed versions

Vulnerability changelog

What's Changed

New features
* New STEPS blending module by RubenImhoff cvelascof ladc wdewettin in 233 (including 231, 232, 236, 255)
* New linear blending module by wdewettin in https://github.com/pySTEPS/pysteps/pull/229
* New SAL verification module by EsmailGhaemi in https://github.com/pySTEPS/pysteps/pull/248

Docs and others
* Update contributing guide by aperezhortal in 241
* Use new theme for docs by dnerini in https://github.com/pySTEPS/pysteps/pull/259
* Replace miniconda by micromamba in CI by aperezhortal in https://github.com/pySTEPS/pysteps/pull/257
* Apply black new stable release (22.1.0) by dnerini in https://github.com/pySTEPS/pysteps/pull/261
* Set minimum python version to 3.7 by dnerini in https://github.com/pySTEPS/pysteps/pull/253

Breaking changes
* Remove deprecated plotting options by dnerini in https://github.com/pySTEPS/pysteps/pull/266


New Contributors
* EsmailGhaemi made his first contribution in https://github.com/pySTEPS/pysteps/pull/248
* wdewettin made his first contribution in 229 and 233
* ladc made her first contribution in 233

**Full Changelog**: https://github.com/pySTEPS/pysteps/compare/v1.5.1...v1.6.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
HIGH