PyPi: Label-Studio-Converter

CVE-2021-25289

Transitive

Safety vulnerability ID: 50648

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 19, 2021 Updated at Jan 30, 2024
Scan your Python projects for vulnerabilities →

Advisory

Label-studio-converter 0.0.43 updates its dependency 'pillow' to v8.3.1 to include security fixes.

Affected package

label-studio-converter

Latest version: 0.0.58

Format converter add-on for Label Studio

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Fix with encoding at all file openings by makseq in https://github.com/heartexlabs/label-studio-converter/pull/5
* BrushLabels to numpy and png. by makseq in https://github.com/heartexlabs/label-studio-converter/pull/9
* Take latest completion that is not skipped by RasmusEdvardsen in https://github.com/heartexlabs/label-studio-converter/pull/7
* Fix CoNLL export to handle all whitespaces by hannukle in https://github.com/heartexlabs/label-studio-converter/pull/13
* Support for COCO segmentation labels by vkhizanov in https://github.com/heartexlabs/label-studio-converter/pull/14
* Relax dependencies requests and Pillow to allow the whole major versi… by vegai in https://github.com/heartexlabs/label-studio-converter/pull/21
* Fix Span Check and multiple whitespace bug in ConLL Conversion by jbogensperger in https://github.com/heartexlabs/label-studio-converter/pull/20
* Fixed bug in converter init for brushlabels by bram2506 in https://github.com/heartexlabs/label-studio-converter/pull/26
* Feature/brush import by bram2506 in https://github.com/heartexlabs/label-studio-converter/pull/25
* Multi annotations and annotator support by makseq in https://github.com/heartexlabs/label-studio-converter/pull/32
* Update converter descriptions by smoreface in https://github.com/heartexlabs/label-studio-converter/pull/31
* Add YOLO export function by johnson7788 in https://github.com/heartexlabs/label-studio-converter/pull/22
* [ext] Bump Pillow to match python 3.9 by farioas in https://github.com/heartexlabs/label-studio-converter/pull/42
* [ext] Make optional resource downloading in converter by makseq in https://github.com/heartexlabs/label-studio-converter/pull/43
* [ext] Bump Pillow version for security reasons by triklozoid in https://github.com/heartexlabs/label-studio-converter/pull/44
* [ext] YOLO to Label Studio JSON converter by makseq in https://github.com/heartexlabs/label-studio-converter/pull/46
* add `supercategory` field to COCO categories by fcakyon in https://github.com/heartexlabs/label-studio-converter/pull/48
* [fix] Fix github issue 1115 - different category ids for same label c… by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/50
* Fix info field in coco format by twsl in https://github.com/heartexlabs/label-studio-converter/pull/55
* fix [issue64](https://github.com/heartexlabs/label-studio-converter/… by loveychen in https://github.com/heartexlabs/label-studio-converter/pull/65
* Speed up encode_rle function by 250-500x by csaroff in https://github.com/heartexlabs/label-studio-converter/pull/52
* DEV-1228: fix condition for 'O' tags in CONLL2003 by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/71
* [fix] Fix parse config by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/60
* DEV-1445: Fix YOLO export to have sorted classes by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/75
* Fix YOLO coordinate deviation of rotated rectangle by changrq in https://github.com/heartexlabs/label-studio-converter/pull/73
* Bump pillow from 8.3.2 to 9.0.0 by dependabot in https://github.com/heartexlabs/label-studio-converter/pull/77
* Bump nltk from 3.5 to 3.6.6 by dependabot in https://github.com/heartexlabs/label-studio-converter/pull/76
* fix: DEV-1525: Fix CONNL converter for complicated configs by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/79
* docs: Update slack invite link by farioas in https://github.com/heartexlabs/label-studio-converter/pull/83
* Bump pillow from 9.0.0 to 9.0.1 by dependabot in https://github.com/heartexlabs/label-studio-converter/pull/86
* Update brush.py by aryanvdesh in https://github.com/heartexlabs/label-studio-converter/pull/90
* YOLO format - change to save multi-label by jangsiye in https://github.com/heartexlabs/label-studio-converter/pull/88
* [fix] Fixing COCO converter to include all images from dataset by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/57
* fix: DEV-2082: Add support "All Tasks" export option by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/94
* fix: DEV-2041 fix setup.py to be used as brew resource by nikitabelonogov in https://github.com/heartexlabs/label-studio-converter/pull/96
* fix: voc should not strip extension from filenames by brettp in https://github.com/heartexlabs/label-studio-converter/pull/100
* Fix out-type when is "predictions" by alebmutt in https://github.com/heartexlabs/label-studio-converter/pull/107
* fix: DEV-2095: Fix runtime error when duration is not extracted by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/102
* fix: DEV-2139: Fix annotation_id is provided as float value in CSV export by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/99
* fix: DEV-2139: Fix annotation_id is provided as float value in CSV export by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/109
* fix: DEV-1923: Add workflow as separate change by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/110
* fix for YOLO export with rotated rectangle annotations by ferenc-hechler in https://github.com/heartexlabs/label-studio-converter/pull/103
* [ext] COCO & PathTrack imports by makseq in https://github.com/heartexlabs/label-studio-converter/pull/69
* fix: DEV-2792: Add YOLO and VOC export image without bounding box by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/113
* fix: DEV-2827: get_local_path doesn't work for local-files by KonstantinKorotaev in https://github.com/heartexlabs/label-studio-converter/pull/115
* ci: DEV-2733: Add PR labeler by nikitabelonogov in https://github.com/heartexlabs/label-studio-converter/pull/116
* ci: DEV-2733: Release Pipeline by nikitabelonogov in https://github.com/heartexlabs/label-studio-converter/pull/117
* ci: DEV-2733: Create LS PR on release by nikitabelonogov in https://github.com/heartexlabs/label-studio-converter/pull/119
* fix: DEV-3164: Remove potential data exposure from logs by niklub in https://github.com/heartexlabs/label-studio-converter/pull/120

New Contributors
* makseq made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/5
* RasmusEdvardsen made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/7
* hannukle made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/13
* vkhizanov made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/14
* vegai made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/21
* jbogensperger made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/20
* bram2506 made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/26
* smoreface made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/31
* johnson7788 made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/22
* farioas made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/42
* triklozoid made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/44
* fcakyon made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/48
* KonstantinKorotaev made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/50
* twsl made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/55
* loveychen made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/65
* csaroff made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/52
* changrq made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/73
* dependabot made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/77
* aryanvdesh made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/90
* jangsiye made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/88
* nikitabelonogov made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/96
* brettp made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/100
* alebmutt made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/107
* ferenc-hechler made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/103
* niklub made their first contribution in https://github.com/heartexlabs/label-studio-converter/pull/120

**Full Changelog**: https://github.com/heartexlabs/label-studio-converter/commits/0.0.43

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH

CVSS v2 Details

HIGH 7.5
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL