Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump fastapi from 0.95.2 to 0.109.1 #19

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Bump fastapi from 0.95.2 to 0.109.1

b890444
Select commit
Loading
Failed to load commit list.
Open

Bump fastapi from 0.95.2 to 0.109.1 #19

Bump fastapi from 0.95.2 to 0.109.1
b890444
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
Wiz Inc. (a28a8b7b4c) / Wiz Vulnerability Scanner completed Feb 5, 2024 in 2s

Wiz Vulnerability Scanner

Greetings, Script Sorcerer! 📜

The compass needle of Wiz's discovery pointed to paths lined with newfound discoveries. 🧭🌟

Exposing Vulnerabilities with Wiz 🪄

🔮 Vulnerabilities Detected: 37

― Note from Wiz: "Your code is pure magic - keep conjuring! 🪄✨"

Annotations

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

mlflow:1.30.1

Detected Vulnerabilities:
  CVE-2023-6015, Severity: Critical, Source: https://github.com/advisories/GHSA-f798-qm4r-23r5
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.8.1
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6568, Severity: Medium, Source: https://github.com/advisories/GHSA-vwhf-3v6x-wff8
    CVSS score: 6.1, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6709, Severity: High, Source: https://github.com/advisories/GHSA-cxfr-5q3r-2rc2
    CVSS score: 8.8, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6909, Severity: High, Source: https://github.com/advisories/GHSA-5r3q-93q3-f978
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6940, Severity: High, Source: https://github.com/advisories/GHSA-hvc6-42vf-jhf8
    CVSS score: 8.8, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-1176, Severity: Low, Source: https://github.com/advisories/GHSA-wp72-7hj9-5265
    CVSS score: 3.3, CVSS exploitability score: 1.8
    🩹 Fixed version: 2.2.1
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-1177, Severity: Critical, Source: https://github.com/advisories/GHSA-xg73-94fp-g449
    CVSS score: 9.8, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.2.1
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6975, Severity: Critical, Source: https://github.com/advisories/GHSA-hh8p-p8mp-gqhm
    CVSS score: 9.8, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6976, Severity: High, Source: https://github.com/advisories/GHSA-wv8q-4f85-2p8p
    CVSS score: 8.8, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6014, Severity: Critical, Source: https://github.com/advisories/GHSA-4qq5-mxxx-m6gg
    CVSS score: 9.8, CVSS exploitability score: 3.9
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6018, Severity: Critical, Source: https://github.com/advisories/GHSA-5p3h-7fwh-92rc
    CVSS score: 9.8, CVSS exploitability score: 3.9
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-43472, Severity: High, Source: https://github.com/advisories/GHSA-wqxf-447m-6f5f
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.9.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6974, Severity: Critical, Source: https://github.com/advisories/GHSA-59v3-898r-qwhj
    CVSS score: 9.8, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6977, Severity: High, Source: https://github.com/advisories/GHSA-qg8p-32gr-gh6x
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  GHSA-83fm-w79m-64r5, Severity: Critical, Source: https://github.com/advisories/GHSA-83fm-w79m-64r5
    🩹 Fixed version: 2.3.1
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-30172, Severity: High, Source: https://github.com/advisories/GHSA-wc6j-5g83-xfm6
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.0.0-rc0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-3765, Severity: Critical, Source: https://github.com/advisories/GHSA-fmxj-6h9g-6vw3
    CVSS score: 10.0, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.5.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-4033, Severity: High, Source: https://github.com/advisories/GHSA-ffw3-6378-cqgp
    CVSS score: 7.8, CVSS exploitability score: 1.8
    🩹 Fixed version: 2.6.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6753, Severity: High, Source: https://github.com/advisories/GHSA-v945-r3rc-6fjm
    CVSS score: 8.8, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-6831, Severity: Critical, Source: https://github.com/advisories/GHSA-554w-xh4j-8w64
    CVSS score: 8.1, CVSS exploitability score: 2.8
    🩹 Fixed version: 2.9.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-2356, Severity: Critical, Source: https://github.com/advisories/GHSA-x422-6qhv-p29g
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.3.1
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-2780, Severity: Critical, Source: https://github.com/advisories/GHSA-wjq3-7jxx-whj9
    CVSS score: 9.8, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.3.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

certifi:2023.5.7

Detected Vulnerabilities:
  CVE-2023-37920, Severity: High, Source: https://github.com/advisories/GHSA-xqr8-7jwr-rhp7
    CVSS score: 9.8, CVSS exploitability score: 3.9
    🩹 Fixed version: 2023.7.22
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

gitpython:3.1.32

Detected Vulnerabilities:
  CVE-2023-40590, Severity: High, Source: https://github.com/advisories/GHSA-wfm5-v35h-vwf4
    CVSS score: 7.8, CVSS exploitability score: 1.8
    🩹 Fixed version: 3.1.33
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-41040, Severity: Medium, Source: https://github.com/advisories/GHSA-cwvm-v4w8-q58c
    CVSS score: 6.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 3.1.37
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2024-22190, Severity: High, Source: https://github.com/advisories/GHSA-2mqj-m65w-jghx
    CVSS score: 7.8, CVSS exploitability score: 1.8
    🩹 Fixed version: 3.1.41
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

grpcio:1.56.0

Detected Vulnerabilities:
  CVE-2023-33953, Severity: High, Source: https://github.com/advisories/GHSA-496j-2rq6-j6cc
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 1.56.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-4785, Severity: High, Source: https://nvd.nist.gov/vuln/detail/CVE-2023-4785
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 1.56.2
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

scikit-learn:1.0.2

Detected Vulnerabilities:
  CVE-2020-28975, Severity: High, Source: https://nvd.nist.gov/vuln/detail/CVE-2020-28975
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 1.1.0-rc1
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check failure on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

transformers:4.30.2

Detected Vulnerabilities:
  CVE-2023-6730, Severity: Critical, Source: https://github.com/advisories/GHSA-3863-2447-669p
    CVSS score: 8.8, CVSS exploitability score: 2.8
    🩹 Fixed version: 4.36.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-7018, Severity: High, Source: https://github.com/advisories/GHSA-v68g-wm8c-6x7j
    CVSS score: 7.8, CVSS exploitability score: 1.8
    🩹 Fixed version: 4.36.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check warning on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

ipython:7.34.0

Detected Vulnerabilities:
  CVE-2023-24816, Severity: Medium, Source: https://github.com/advisories/GHSA-29gw-9793-fvw7
    CVSS score: 7.0, CVSS exploitability score: 1.0
    🩹 Fixed version: 8.10.0
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check warning on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

tornado:6.3.2

Detected Vulnerabilities:
  GHSA-qppv-j76h-2rpx, Severity: Medium, Source: https://github.com/advisories/GHSA-qppv-j76h-2rpx
    🩹 Fixed version: 6.3.3
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check warning on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

werkzeug:2.3.6

Detected Vulnerabilities:
  CVE-2023-46136, Severity: Medium, Source: https://github.com/advisories/GHSA-hrfv-mqp8-q5rw
    CVSS score: 7.5, CVSS exploitability score: 3.9
    🩹 Fixed version: 2.3.8
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check warning on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

urllib3:1.26.16

Detected Vulnerabilities:
  CVE-2023-43804, Severity: Medium, Source: https://github.com/advisories/GHSA-v845-jxx5-vc9f
    CVSS score: 8.1, CVSS exploitability score: 2.8
    🩹 Fixed version: 1.26.17
    💥 Has public exploit
    🧨 Has CISA KEV exploit
  CVE-2023-45803, Severity: Medium, Source: https://github.com/advisories/GHSA-g4mx-q9vg-27p4
    CVSS score: 4.2, CVSS exploitability score: 0.5
    🩹 Fixed version: 1.26.18
    💥 Has public exploit
    🧨 Has CISA KEV exploit

Check warning on line 1 in poetry.lock

See this annotation in the file changed.

@wiz-inc-a28a8b7b4c wiz-inc-a28a8b7b4c / Wiz Vulnerability Scanner

jinja2:3.1.2

Detected Vulnerabilities:
  CVE-2024-22195, Severity: Medium, Source: https://github.com/advisories/GHSA-h5c8-rqwp-cp95
    CVSS score: 6.1, CVSS exploitability score: 2.8
    🩹 Fixed version: 3.1.3
    💥 Has public exploit
    🧨 Has CISA KEV exploit