PyPi: Py-Pure-Client

CVE-2023-45803

Safety vulnerability ID: 63006

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Oct 17, 2023 Updated at Apr 26, 2024
Scan your Python projects for vulnerabilities →

Advisory

Py-pure-client 2.29 and prior versions ship with vulnerable dependencies (urllib3 >= 1.26.17).

Affected package

py-pure-client

Latest version: 1.50.0

Pure Storage Python clients for FlashArray, FlashBlade, and Pure1 APIs

Affected versions

Fixed versions

Vulnerability changelog

Kerberos security options for NFS v4.1 in FA File now supported: "krb5", "krb5i", "krb5p"

Endpoints enhancements
- For the Directory Service Role endpoint the role attribute is now a ReferenceNoId type (previously was a FixedReferenceNoId).
- Continuation token support for:
- get_volume_snapshots_transfer
- get_protection_group_snapshot_transfer
- CBS Capacity Expansion endpoints now publicly available to users for both PAZ and PAWS
- listing supported capacity values
- setting desired capacity
- getting the status of capacity update
- Expand GET /software-patches with fields:
- ha_reduction_required
- Expand POST /software-patches with fields:
- allow_ha_reduction

Client enhancements
- Dynamic import of versioned clients
- Updated urllib3 >= 1.26.17
- Removed upper limit for python-dateutil

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 4.2

CVSS v3 Details

MEDIUM 4.2
Attack Vector (AV)
ADJACENT_NETWORK
Attack Complexity (AC)
HIGH
Privileges Required (PR)
HIGH
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
NONE
Availability Availability (A)
NONE