PyPi: Crypto-Candlesticks

CVE-2020-28493

Transitive

Safety vulnerability ID: 39697

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 01, 2021 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Crypto-candlesticks 0.1.5 updates its dependency 'jinja2' to v2.11.3 to include a security fix.

Affected package

crypto-candlesticks

Latest version: 0.2.1

Download candlestick data fast & easy for analysis

Affected versions

Fixed versions

Vulnerability changelog

What's new

Fix jinja2 vulnerability ID 39525d103864
Replace "Writting" with "writing" (90) juandes

Bumps:

* chore: bump importlib-metadata from 3.4.0 to 3.7.0 (112) dependabot
* chore: bump wemake-python-styleguide from 0.15.1 to 0.15.2 (110) dependabot
* chore: bump mypy from 0.800 to 0.812 (108) dependabot
* chore: bump darglint from 1.6.0 to 1.7.0 (107) dependabot
* chore: bump sphinx from 3.5.0 to 3.5.1 (109) dependabot
* chore: bump rich from 9.10.0 to 9.11.1 (106) dependabot
* chore: bump sphinx from 3.4.3 to 3.5.0 (103) dependabot
* chore: bump release-drafter/release-drafter from v5.13.0 to v5.14.0 (105) dependabot
* chore: bump wemake-python-styleguide from 0.14.1 to 0.15.1 (104) dependabot
* chore: bump pre-commit from 2.10.0 to 2.10.1 (101) dependabot
* chore: bump numpy from 1.20.0 to 1.20.1 (102) dependabot
* chore: bump darglint from 1.5.8 to 1.6.0 (99) dependabot
* chore: bump numpy from 1.19.5 to 1.20.0 (100) dependabot
* chore: bump pytest-cov from 2.11.0 to 2.11.1 (95) dependabot
* chore: bump mypy from 0.790 to 0.800 (96) dependabot
* chore: bump rich from 9.8.2 to 9.9.0 (97) dependabot
* chore: bump xdoctest from 0.15.0 to 0.15.2 (98) dependabot
* chore: bump pytest-cov from 2.10.1 to 2.11.0 (94) dependabot
* chore: bump release-drafter/release-drafter from v5.12.1 to v5.13.0 (93) dependabot
* chore: bump rich from 9.8.0 to 9.8.2 (91) dependabot
* chore: bump safety from 1.10.2 to 1.10.3 (92) dependabot

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 5.3

CVSS v3 Details

MEDIUM 5.3
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
LOW

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Impact (A)
PARTIAL