PyPi: Tulflow

CVE-2022-45402

Transitive

Safety vulnerability ID: 58741

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Nov 15, 2022 Updated at May 13, 2024
Scan your Python projects for vulnerabilities →

Advisory

Tulflow 0.9.1 updates its dependency 'apache-airflow' to v2.4.3 to include security fixes.

Affected package

tulflow

Latest version: 0.10.0

Package of Temple University Library Indexing & ETL functions used by Airflow.

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Bump apache-airflow from 2.3.0 to 2.3.2 by dependabot in https://github.com/tulibraries/tulflow/pull/269
* Bump lxml from 4.8.0 to 4.9.1 by dependabot in https://github.com/tulibraries/tulflow/pull/285
* Bump requests from 2.27.1 to 2.28.0 by dependabot in https://github.com/tulibraries/tulflow/pull/288
* Bump apache-airflow-providers-amazon from 3.4.0 to 4.0.0 by dependabot in https://github.com/tulibraries/tulflow/pull/274
* Bump apache-airflow-providers-sftp from 2.6.0 to 3.0.0 by dependabot in https://github.com/tulibraries/tulflow/pull/275
* Bump marshmallow from 3.15.0 to 3.17.0 by dependabot in https://github.com/tulibraries/tulflow/pull/283
* Bump moto from 3.1.10 to 3.1.16 by dependabot in https://github.com/tulibraries/tulflow/pull/282
* Bump apache-airflow-providers-ssh from 2.4.4 to 3.1.0 by dependabot in https://github.com/tulibraries/tulflow/pull/290
* Bump apache-airflow-providers-ftp from 2.1.2 to 3.1.0 by dependabot in https://github.com/tulibraries/tulflow/pull/291
* Update airflow version by sensei100 in https://github.com/tulibraries/tulflow/pull/325
* Bump pylint from 2.15.4 to 2.15.5 by dependabot in https://github.com/tulibraries/tulflow/pull/329
* Bump wheel from 0.37.1 to 0.38.3 by dependabot in https://github.com/tulibraries/tulflow/pull/337
* Bump sqlalchemy from 1.4.41 to 1.4.43 by dependabot in https://github.com/tulibraries/tulflow/pull/336
* Bump wheel from 0.38.3 to 0.38.4 by dependabot in https://github.com/tulibraries/tulflow/pull/338
* Bump setuptools from 65.4.1 to 65.6.0 by dependabot in https://github.com/tulibraries/tulflow/pull/348
* Bump moto from 4.0.7 to 4.0.10 by dependabot in https://github.com/tulibraries/tulflow/pull/347
* Bump apache-airflow-providers-ftp from 3.1.0 to 3.2.0 by dependabot in https://github.com/tulibraries/tulflow/pull/346
* Bump apache-airflow-providers-sftp from 4.1.0 to 4.2.0 by dependabot in https://github.com/tulibraries/tulflow/pull/345
* Bump apache-airflow-providers-ssh from 3.2.0 to 3.3.0 by dependabot in https://github.com/tulibraries/tulflow/pull/344
* Bump apache-airflow-providers-amazon from 6.0.0 to 6.1.0 by dependabot in https://github.com/tulibraries/tulflow/pull/342
* Bump sqlalchemy from 1.4.43 to 1.4.44 by dependabot in https://github.com/tulibraries/tulflow/pull/341
* Bump marshmallow from 3.18.0 to 3.19.0 by dependabot in https://github.com/tulibraries/tulflow/pull/339
* Bump setuptools from 65.6.0 to 65.6.3 by dependabot in https://github.com/tulibraries/tulflow/pull/352
* Bump certifi from 2022.9.24 to 2022.12.7 by dependabot in https://github.com/tulibraries/tulflow/pull/360
* Bump lxml from 4.9.1 to 4.9.2 by dependabot in https://github.com/tulibraries/tulflow/pull/365
* Bump numpy from 1.23.4 to 1.24.1 by dependabot in https://github.com/tulibraries/tulflow/pull/366
* Update airflow due to security vulnerability by sensei100 in https://github.com/tulibraries/tulflow/pull/378
* Bump setuptools from 66.1.0 to 66.1.1 by dependabot in https://github.com/tulibraries/tulflow/pull/379
* New version for release by sensei100 in https://github.com/tulibraries/tulflow/pull/380


**Full Changelog**: https://github.com/tulibraries/tulflow/compare/v0.9.0...v0.9.1

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.1

CVSS v3 Details

MEDIUM 6.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
CHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
LOW
Availability Availability (A)
NONE