Safety vulnerability ID: 51541
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Ravenpy 0.9.0 includes a fix for CVE-2007-4559: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Latest version: 0.16.0
A Python wrapper to setup and run the hydrologic modelling framework Raven.
-----
- Add support for the command `:RedirectToFile`. Tested for grid weights only.
- Add support for the command `:WriteForcingFunctions`.
- Patch directory traversal vulnerability (`CVE-2007-4559 <(https://github.com/advisories/GHSA-gw9q-c7gh-j9vm>`_).
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application