PyPi: Syft

CVE-2023-41039

Transitive

Safety vulnerability ID: 61959

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Aug 30, 2023 Updated at Apr 28, 2024
Scan your Python projects for vulnerabilities →

Advisory

Syft 0.8.2b40 updates its dependency 'RestrictedPython' to 6.2 to include a security fix.
https://github.com/OpenMined/PySyft/pull/8177/commits/5fb618fbf04ed26cae34d635ddf21d05100367ca

Affected package

syft

Latest version: 0.8.6

Perform numpy-like analysis on data that remains in someone elses server

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* refactor: remove unneeded conditions in login/login_as_guest by tcp in https://github.com/OpenMined/PySyft/pull/8151
* [WIP] Deploy to AWS tutorial by shubham3121 in https://github.com/OpenMined/PySyft/pull/7664
* Fixed security issues and bumped versions by madhavajay in https://github.com/OpenMined/PySyft/pull/8177
* Return a new client with SyftClient.login by kiendang in https://github.com/OpenMined/PySyft/pull/8159
* fix: reduce fe to metadata info by tcp in https://github.com/OpenMined/PySyft/pull/8176
* Disabling frontend e2e because there are none and the tox task breaks by madhavajay in https://github.com/OpenMined/PySyft/pull/8184


**Full Changelog**: https://github.com/OpenMined/PySyft/compare/v0.8.2b39...v0.8.2b40

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.7

CVSS v3 Details

HIGH 7.7
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
LOW
User Interaction (UI)
NONE
Scope (S)
CHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
NONE
Availability Availability (A)
NONE