Safety vulnerability ID: 51644
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Modelstore 0.0.76 includes a fix for CVE-2007-4559: Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
Latest version: 0.0.81
modelstore is a library for versioning, exporting, storing, and loading machine learning models
**🐛 Bug fixes & general updates**
A workaround for a security issue in the Python `tarfile` library was added ([203](https://github.com/operatorai/modelstore/pull/203), thanks [TrellixVulnTeam](https://github.com/TrellixVulnTeam)).
A security upgrade to the `protobuf` was merged ([202](https://github.com/operatorai/modelstore/pull/202), thanks dependabot) - this impacts developers of this library only.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application