PyPi: Glances

CVE-2020-24025

Transitive

Safety vulnerability ID: 42752

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jan 11, 2021 Updated at Mar 23, 2024
Scan your Python projects for vulnerabilities →

Advisory

Glances 3.2.4 updates WebUI dependencies (particularly, "node-sass") to include a security fix.
https://github.com/nicolargo/glances/commit/d3560d403db1d8133d87f569d3fa3299f5db4a31

Affected package

glances

Latest version: 3.4.0.5

A cross-platform curses-based monitoring tool

Affected versions

Fixed versions

Vulnerability changelog

===============

Bugs corrected:

* Failure to start on Apple M1 Max 1939
* Influxdb2 via SSL 1934
* Update WebUI (security patch). Thanks to notFloran.
* Swith from black <> white theme with the '9' hotkey - Related to issue 976
* Fix: Docker plugin - Invalid IO stats with Arch Linux 1945
* Bug Fix: Docker plugin - Network stats not being displayed 1944
* Fix Grafana CPU temperature panel 1954
* is_disabled name fix 1949
* Fix tipo in documentation 1932
* distutils is deprecated in Python 3.10 1923
* Separate battery percentages 1920
* Update docs and correct make docs-server target in Makefile

Enhancement requests:

* Improve --issue by displaying the second update iteration and not the first one. More relevant
* Improve --issue option with Python version and paths
* Correct an issue on idle display
* Refactor Mem + MemSwap Curse
* Refactor CPU Curses code

Contributors for this version:
* Nicolargo
* RazCrimson
* Floran Brutel
* H4ckerxx44
* Mohamad Mansour
* Néfix Estrada
* Zameer Manji

===============

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 5.3

CVSS v3 Details

MEDIUM 5.3
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
LOW
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
PARTIAL
Availability Impact (A)
NONE