PyPi: Piperider

CVE-2021-3803

Transitive

Safety vulnerability ID: 50270

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 17, 2021 Updated at Nov 23, 2023
Scan your Python projects for vulnerabilities →

Advisory

Piperider 0.5.0rc1 updates its NPM dependency "nth-check" to v2.0.1 to include a security fix.

Affected package

piperider

Latest version: 0.41.0

PiperRider CLI

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Rotate unsend events by ctiml in https://github.com/InfuseAI/piperider/pull/258
* update: build on every PR; Commit build only upon merge event by jonycfu in https://github.com/InfuseAI/piperider/pull/259
* fix: typo in pypi.yaml by kentwelcome in https://github.com/InfuseAI/piperider/pull/261
* fix: Restore missing numeric properties (merge UI to shared comp) by jonycfu in https://github.com/InfuseAI/piperider/pull/262
* refactor: general-table-column (shared UI) by jonycfu in https://github.com/InfuseAI/piperider/pull/263
* Fix empty description from dbt by even-wei in https://github.com/InfuseAI/piperider/pull/260
* [Fix] sc-27203 Handle the error when load dbt project and profile by kentwelcome in https://github.com/InfuseAI/piperider/pull/264
* Update README.md by hlb in https://github.com/InfuseAI/piperider/pull/269
* Chore: Refactor the profiler by popcornylu in https://github.com/InfuseAI/piperider/pull/267
* Feature: sc-27306 Check datasource connector before running by kentwelcome in https://github.com/InfuseAI/piperider/pull/266
* Enhancement show table column descriptions by ctiml in https://github.com/InfuseAI/piperider/pull/268
* Fix e2e compare-reports hang by ctiml in https://github.com/InfuseAI/piperider/pull/272
* fix(comparison): typo by neighborhood999 in https://github.com/InfuseAI/piperider/pull/274
* Add profiler event handler by popcornylu in https://github.com/InfuseAI/piperider/pull/271
* Refactor date distribution and backend type by wcchang1115 in https://github.com/InfuseAI/piperider/pull/275
* [Refactor] improve codebase by even-wei in https://github.com/InfuseAI/piperider/pull/270
* POC: UI e2e testing (Cypress) by jonycfu in https://github.com/InfuseAI/piperider/pull/265
* Feature/sc 27426/clean up workspace generate assertions by kentwelcome in https://github.com/InfuseAI/piperider/pull/279
* add ci-statics.yaml for separate workflow (PR open, synch) by jonycfu in https://github.com/InfuseAI/piperider/pull/284
* Separate code for compare-reports by ctiml in https://github.com/InfuseAI/piperider/pull/276
* fix(assertions): aggregate piperider and dbt assertions result by neighborhood999 in https://github.com/InfuseAI/piperider/pull/277
* Implement rich progress profiling by ctiml in https://github.com/InfuseAI/piperider/pull/281
* Chore/build statics handle race condition merges by jonycfu in https://github.com/InfuseAI/piperider/pull/286
* Feature: sc-27269 enhance piperider exception handling by kentwelcome in https://github.com/InfuseAI/piperider/pull/273
* Feature: sc-27421 enhance error handling when profiler encounter error by kentwelcome in https://github.com/InfuseAI/piperider/pull/280
* fix: formatting readme (trigger rebuild as well) by jonycfu in https://github.com/InfuseAI/piperider/pull/287
* fix: sc-27432 Add a comment if a recommended assertion is suggested to … by kentwelcome in https://github.com/InfuseAI/piperider/pull/283
* Refactor dbt adapter by ctiml in https://github.com/InfuseAI/piperider/pull/278
* Feature/sc 27304/refactor the profiler by popcornylu in https://github.com/InfuseAI/piperider/pull/285
* Fix no module named 'piperider_cli.adapter' problem by popcornylu in https://github.com/InfuseAI/piperider/pull/289
* [Feature] Modify the layout of assertions result by kentwelcome in https://github.com/InfuseAI/piperider/pull/288
* fix quantile calculation by wcchang1115 in https://github.com/InfuseAI/piperider/pull/290
* Feature/sc 27309/UI runtime schema validation by jonycfu in https://github.com/InfuseAI/piperider/pull/295
* Update README.md by kentwelcome in https://github.com/InfuseAI/piperider/pull/296
* Remove null properties from column results by ctiml in https://github.com/InfuseAI/piperider/pull/293
* feature: add string column mismatch handler by wcchang1115 in https://github.com/InfuseAI/piperider/pull/291
* [Fix] sc-27574 Fix GitHub report security alert by kentwelcome in https://github.com/InfuseAI/piperider/pull/297
* Feature/sc 27377/compare reports rename all base input terms by jonycfu in https://github.com/InfuseAI/piperider/pull/300
* Fix test status calculation by ctiml in https://github.com/InfuseAI/piperider/pull/299
* Workaround for sqlalchemy problem by popcornylu in https://github.com/InfuseAI/piperider/pull/304
* fix: count of the last bin missing in distribution metric by wcchang1115 in https://github.com/InfuseAI/piperider/pull/302
* Rename base/input to base/target in TUI by ctiml in https://github.com/InfuseAI/piperider/pull/301
* fix: add empty assertion content handler by wcchang1115 in https://github.com/InfuseAI/piperider/pull/306
* [Feature] sc-27581 Collect user input without using lib py-inquirer by kentwelcome in https://github.com/InfuseAI/piperider/pull/303
* [Enhance] sc-27640 Add 'init' comment to the event log whitelist by kentwelcome in https://github.com/InfuseAI/piperider/pull/308
* Update version to 0.5.0 by kentwelcome in https://github.com/InfuseAI/piperider/pull/312

New Contributors
* hlb made their first contribution in https://github.com/InfuseAI/piperider/pull/269

**Full Changelog**: https://github.com/InfuseAI/piperider/compare/v0.4.1...v0.5.0-rc.1

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
HIGH

CVSS v2 Details

MEDIUM 5.0
Access Vector (AV)
NETWORK
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Impact (A)
PARTIAL