PyPi: Panther-Analysis-Tool

CVE-2023-49081

Transitive

Safety vulnerability ID: 67504

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Nov 30, 2023 Updated at May 07, 2024
Scan your Python projects for vulnerabilities →

Advisory

Panther-analysis-tool version 0.45.0 has upgraded its aiohttp library to version 3.9.2 from the previous 3.8.6, addressing security concerns highlighted by CVE-2023-49081

Affected package

panther-analysis-tool

Latest version: 0.49.0

Panther command line interface for writing, testing, and packaging policies/rules.

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Add colors to test output by le4ker in https://github.com/panther-labs/panther_analysis_tool/pull/473
* Bump black from 23.7.0 to 24.3.0 by le4ker in https://github.com/panther-labs/panther_analysis_tool/pull/474
* [Snyk] Fix for 5 vulnerabilities by le4ker in https://github.com/panther-labs/panther_analysis_tool/pull/476

**Full Changelog**: https://github.com/panther-labs/panther_analysis_tool/compare/v0.44.0...v0.45.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 5.3

CVSS v3 Details

MEDIUM 5.3
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
LOW
Availability Availability (A)
NONE