Bump fastapi from 0.95.2 to 0.109.1 #19
Wiz Vulnerability Scanner
Greetings, Script Sorcerer! 📜
The compass needle of Wiz's discovery pointed to paths lined with newfound discoveries. 🧭🌟
Exposing Vulnerabilities with Wiz 🪄
🔮 Vulnerabilities Detected: 37
― Note from Wiz: "Your code is pure magic - keep conjuring! 🪄✨"
Annotations
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
mlflow:1.30.1
Detected Vulnerabilities:
CVE-2023-6015, Severity: Critical, Source: https://github.com/advisories/GHSA-f798-qm4r-23r5
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.8.1
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6568, Severity: Medium, Source: https://github.com/advisories/GHSA-vwhf-3v6x-wff8
CVSS score: 6.1, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6709, Severity: High, Source: https://github.com/advisories/GHSA-cxfr-5q3r-2rc2
CVSS score: 8.8, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6909, Severity: High, Source: https://github.com/advisories/GHSA-5r3q-93q3-f978
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6940, Severity: High, Source: https://github.com/advisories/GHSA-hvc6-42vf-jhf8
CVSS score: 8.8, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-1176, Severity: Low, Source: https://github.com/advisories/GHSA-wp72-7hj9-5265
CVSS score: 3.3, CVSS exploitability score: 1.8
🩹 Fixed version: 2.2.1
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-1177, Severity: Critical, Source: https://github.com/advisories/GHSA-xg73-94fp-g449
CVSS score: 9.8, CVSS exploitability score: 3.9
🩹 Fixed version: 2.2.1
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6975, Severity: Critical, Source: https://github.com/advisories/GHSA-hh8p-p8mp-gqhm
CVSS score: 9.8, CVSS exploitability score: 3.9
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6976, Severity: High, Source: https://github.com/advisories/GHSA-wv8q-4f85-2p8p
CVSS score: 8.8, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6014, Severity: Critical, Source: https://github.com/advisories/GHSA-4qq5-mxxx-m6gg
CVSS score: 9.8, CVSS exploitability score: 3.9
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6018, Severity: Critical, Source: https://github.com/advisories/GHSA-5p3h-7fwh-92rc
CVSS score: 9.8, CVSS exploitability score: 3.9
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-43472, Severity: High, Source: https://github.com/advisories/GHSA-wqxf-447m-6f5f
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.9.0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6974, Severity: Critical, Source: https://github.com/advisories/GHSA-59v3-898r-qwhj
CVSS score: 9.8, CVSS exploitability score: 3.9
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6977, Severity: High, Source: https://github.com/advisories/GHSA-qg8p-32gr-gh6x
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
GHSA-83fm-w79m-64r5, Severity: Critical, Source: https://github.com/advisories/GHSA-83fm-w79m-64r5
🩹 Fixed version: 2.3.1
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-30172, Severity: High, Source: https://github.com/advisories/GHSA-wc6j-5g83-xfm6
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.0.0-rc0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-3765, Severity: Critical, Source: https://github.com/advisories/GHSA-fmxj-6h9g-6vw3
CVSS score: 10.0, CVSS exploitability score: 3.9
🩹 Fixed version: 2.5.0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-4033, Severity: High, Source: https://github.com/advisories/GHSA-ffw3-6378-cqgp
CVSS score: 7.8, CVSS exploitability score: 1.8
🩹 Fixed version: 2.6.0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6753, Severity: High, Source: https://github.com/advisories/GHSA-v945-r3rc-6fjm
CVSS score: 8.8, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-6831, Severity: Critical, Source: https://github.com/advisories/GHSA-554w-xh4j-8w64
CVSS score: 8.1, CVSS exploitability score: 2.8
🩹 Fixed version: 2.9.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-2356, Severity: Critical, Source: https://github.com/advisories/GHSA-x422-6qhv-p29g
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.3.1
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-2780, Severity: Critical, Source: https://github.com/advisories/GHSA-wjq3-7jxx-whj9
CVSS score: 9.8, CVSS exploitability score: 3.9
🩹 Fixed version: 2.3.0
💥 Has public exploit
🧨 Has CISA KEV exploit
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
certifi:2023.5.7
Detected Vulnerabilities:
CVE-2023-37920, Severity: High, Source: https://github.com/advisories/GHSA-xqr8-7jwr-rhp7
CVSS score: 9.8, CVSS exploitability score: 3.9
🩹 Fixed version: 2023.7.22
💥 Has public exploit
🧨 Has CISA KEV exploit
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
gitpython:3.1.32
Detected Vulnerabilities:
CVE-2023-40590, Severity: High, Source: https://github.com/advisories/GHSA-wfm5-v35h-vwf4
CVSS score: 7.8, CVSS exploitability score: 1.8
🩹 Fixed version: 3.1.33
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-41040, Severity: Medium, Source: https://github.com/advisories/GHSA-cwvm-v4w8-q58c
CVSS score: 6.5, CVSS exploitability score: 3.9
🩹 Fixed version: 3.1.37
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2024-22190, Severity: High, Source: https://github.com/advisories/GHSA-2mqj-m65w-jghx
CVSS score: 7.8, CVSS exploitability score: 1.8
🩹 Fixed version: 3.1.41
💥 Has public exploit
🧨 Has CISA KEV exploit
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
grpcio:1.56.0
Detected Vulnerabilities:
CVE-2023-33953, Severity: High, Source: https://github.com/advisories/GHSA-496j-2rq6-j6cc
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 1.56.2
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-4785, Severity: High, Source: https://nvd.nist.gov/vuln/detail/CVE-2023-4785
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 1.56.2
💥 Has public exploit
🧨 Has CISA KEV exploit
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
scikit-learn:1.0.2
Detected Vulnerabilities:
CVE-2020-28975, Severity: High, Source: https://nvd.nist.gov/vuln/detail/CVE-2020-28975
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 1.1.0-rc1
💥 Has public exploit
🧨 Has CISA KEV exploit
Check failure on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
transformers:4.30.2
Detected Vulnerabilities:
CVE-2023-6730, Severity: Critical, Source: https://github.com/advisories/GHSA-3863-2447-669p
CVSS score: 8.8, CVSS exploitability score: 2.8
🩹 Fixed version: 4.36.0
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-7018, Severity: High, Source: https://github.com/advisories/GHSA-v68g-wm8c-6x7j
CVSS score: 7.8, CVSS exploitability score: 1.8
🩹 Fixed version: 4.36.0
💥 Has public exploit
🧨 Has CISA KEV exploit
Check warning on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
ipython:7.34.0
Detected Vulnerabilities:
CVE-2023-24816, Severity: Medium, Source: https://github.com/advisories/GHSA-29gw-9793-fvw7
CVSS score: 7.0, CVSS exploitability score: 1.0
🩹 Fixed version: 8.10.0
💥 Has public exploit
🧨 Has CISA KEV exploit
Check warning on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
tornado:6.3.2
Detected Vulnerabilities:
GHSA-qppv-j76h-2rpx, Severity: Medium, Source: https://github.com/advisories/GHSA-qppv-j76h-2rpx
🩹 Fixed version: 6.3.3
💥 Has public exploit
🧨 Has CISA KEV exploit
Check warning on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
werkzeug:2.3.6
Detected Vulnerabilities:
CVE-2023-46136, Severity: Medium, Source: https://github.com/advisories/GHSA-hrfv-mqp8-q5rw
CVSS score: 7.5, CVSS exploitability score: 3.9
🩹 Fixed version: 2.3.8
💥 Has public exploit
🧨 Has CISA KEV exploit
Check warning on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
urllib3:1.26.16
Detected Vulnerabilities:
CVE-2023-43804, Severity: Medium, Source: https://github.com/advisories/GHSA-v845-jxx5-vc9f
CVSS score: 8.1, CVSS exploitability score: 2.8
🩹 Fixed version: 1.26.17
💥 Has public exploit
🧨 Has CISA KEV exploit
CVE-2023-45803, Severity: Medium, Source: https://github.com/advisories/GHSA-g4mx-q9vg-27p4
CVSS score: 4.2, CVSS exploitability score: 0.5
🩹 Fixed version: 1.26.18
💥 Has public exploit
🧨 Has CISA KEV exploit
Check warning on line 1 in poetry.lock
wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner
jinja2:3.1.2
Detected Vulnerabilities:
CVE-2024-22195, Severity: Medium, Source: https://github.com/advisories/GHSA-h5c8-rqwp-cp95
CVSS score: 6.1, CVSS exploitability score: 2.8
🩹 Fixed version: 3.1.3
💥 Has public exploit
🧨 Has CISA KEV exploit