PyPi: Isogeo-Export-Xl

CVE-2020-6802

Transitive

Safety vulnerability ID: 38286

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 24, 2020 Updated at Nov 07, 2023
Scan your Python projects for vulnerabilities →

Advisory

Isogeo-export-xl 1.3.0 updates its dependency 'bleach' to v3.1.1. to include a security fix.

Affected package

isogeo-export-xl

Latest version: 1.3.2

Toolbelt to export metadata from the Isogeo REST API into Microsoft Excel workbooks (.xlsx).

Affected versions

Fixed versions

Vulnerability changelog

Changes:

* 5cf4dc2771dc44f502f00334584afbae23c849ee Merge branch 'master' of https://github.com/isogeo/export-xlsx-py
* 68daeeec974e22f1b650d1ec9349a84352ef7eb5 Bump to 1.3.0 version [ 38 ]
* e50d9cca2b38ce6660abc5f80fb83721b8e6aae8 Merge pull request 42 from isogeo/housekeeping
* 2ab8a3434d6d6b2f9b0b70c36194c6f396b40747 Merge branch 'master' into housekeeping
* 04c6aab4b499ab74372b3828ac5ac0e1fbc4e0c4 Fix setup.py to publish new version on PyPi [ 38 ]
* 662183b84e600a813b06b9c40ce8a7304afaef94 Bump to version 1.2.5 [ 38 ]
* 585f85d92f69a4c10841810a06cab89973a51ea9 Merge pull request 40 from isogeo/reader
* 09d460ee270e50f7390fd2ad4dd65aebf957247b Rename isogeofromxlsx.py to isogeoFromxlsx.py [ 40 ]
* 7f26c2be58ec161544287f41c205834173130db9 Clean isogeoFromxlsx code comment [ 40 ]
* 8e50b90ef10ce4f452e059a020a04d705a868c2c Merge branch 'master' into reader
<details><summary><b>See More</b></summary>

* ea58addcfa2e8bfd7f2c338b4a1de3bf5a6abdd0 Merge pull request 41 from isogeo/housekeeping
* a2ceac5578b27e298181ca8c7185dc7f8ec61235 Merge branch 'master' into housekeeping
* f468e655cbbef6efdbab52441be0ea68fc785c5e Update bleach to fix security alert
* 89644125135963a46605e81340656c88f386e145 Add _inpout folder to .gitignore
* 93c90ffa205d3be577e72a4e45cf70a1118bd505 Fix isogeo-pysdk objects instanciation for subressources
* 6765af6ae925f7a5770280f593cbad32870aee78 Add limitations, licenses and specifications handling [ 40 ]
* ab23b6f6d8bc8cada97c0e1b31fd9582dd87ced7 Update samples import script
* 890d3930f0f27c4fe785b27c0c5ceaee4f842940 Add limitations vocabulary to i18n [ 40 ]
* 4e3bd85b0219674e5b08f967294f9d14ad744ee3 Clean package __init__.py [ 40 ]
* 23ede989da4ef411881e696064c15f540b9f71ed Fix i18n licenses typo [ 40 ]
* 2b526b1b1362d65bf05b3816726827809d443529 Add Licenses and Specifications worksheets to i18n [ 40 ]
* 1fa36d09d160846bb0ca5133c9ebbec557fe3bf0 add docstring and formate the code [ 40 ]
* bcc3492d90d30f6aa2095e392558cf325bfe2b31 add samples [ 38 ]
* ffc5dba0e4fef2d669b1dd84d41f9cb5738a3e95 remove import script
* e4256d2b42efea3ca48b1e9262276c1d37633d7c update import script [ 38 ]
* 5de55a4b9cd5c31130ee075a012dc42238380366 add an import from excel script [ 38 ]
* c610c3146858ec09a781541a207ca12f69ce71f1 update reader inspire themes parsing [ 38 ]
* c9d9c5318a4a16459f3fea57e2de54767769e684 update xlsx reader module [ 38 ]
* 484a1d0bff7ec473f8fac7628beed5e83c84ed7e first 'working' version of reader [ 38 ]
* 99e4060a701dde42d0fbfd13a79d4664aaa66d1b Initiate excel reader module [ 38 ]
* 7012dd942f230da2d7838877cc7cc06e24b6b03c Update gitignore to ignore try files
* f702973e5afe0fc76bfa22af9377118b37911a67 create a script to export md [ 38 ]
* 3b49d5f7ed6ae96098ad9de9f742c0723d87adbd update python_path setting
* 6d6f489a9f8af8e79994a692a427651addc18197 Docs - Add advanced usage
* c40aed906abe576149573bf5926b4c1a20f66439 Docs - upgrade to handle markdown (37)
* ce57de029fa0cb7fce9cdbe277adc18b132f1e58 Allow to pass openpyxl worbook root arguments 34 (36)
* fd14e7839431c18f5197b6d6e3bb3b1013ca8135 Add basic usage (35)
* 3bc96bc42f35b225d705cb8d2e59c019e2d10fe1 Use about values in setup
* 32a40185fb3677e934c2ddffd85e3475a13ba388 Remove comments
* 3a502dd2609ba0a9e307f4b28aa377265fc6ccaf Remove end line
* 5fd2e6507a33f45c98c2b6936738b5e7b5bf4b7b Applying pre-commit hooks
* 2f41af911e327cf4a2f8ef5188449a12fa70a234 Clean up docs
* 7e9ad9ade170f050653771efa226df57517c07f0 Add pre-commit config
* 6d826e065040916a6c344e9a3ca36f606de6ae94 Merge branch 'master' into housekeeping
* 33394434f59b6d6f6d86992acea42e8adbd423f2 Merge branch 'master' into housekeeping
* a744107603e69a062473e76a24ec24dbcd411f01 Bump Isogeo SDK and pytest
* ad90c02cbd83916f6a7275b9b5b2cbf7f3155ec8 CI - Fix backshlash in path
* f12da977a016a1b5259650ce732adb1e0f2aa519 Bump dependencies
* 688d1453f92013f81d8a3cdd9a64e9918b2f931f Merge branch 'master' into housekeeping
* 4eefa0f4f38a0c769d247e045a5f9132c015c25c Merge branch 'master' into housekeeping
* a250598c4e4075353073e8d1328fa909d0c8cfa0 Merge branch 'master' into housekeeping
* dd50e05c0d7b7b9f89218788dca209f58707826a Merge branch 'housekeeping' of https://github.com/isogeo/export-xlsx-py into housekeeping
* 70649e02889b596e2062ceebfc5af40272c47077 fix pypi service endpoint name
* f45d77ce9ea892c4c9a7151a2de4b03a066aa039 Update azure-pipelines.yml for Azure Pipelines
* 6363e2484c3de3a022ece6bfc505017024288d1d bump dependencies

This list of changes was [auto generated](https://dev.azure.com/isogeo/PythonTooling/_build/results?buildId=2676&view=logs).</details>

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.1

CVSS v3 Details

MEDIUM 6.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
CHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
LOW
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 4.3
Access Vector (AV)
NETWORK
Access Complexity (AC)
MEDIUM
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
PARTIAL
Availability Impact (A)
NONE