PyPi: Bokeh

CVE-2021-41182

Transitive

Safety vulnerability ID: 42772

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Oct 26, 2021 Updated at Dec 04, 2024
Scan your Python projects for vulnerabilities →

Advisory

Bokeh 2.4.2 updates its dependency 'jquery-ui' to v1.13.0 to include security fixes.

Affected package

bokeh

Latest version: 3.6.2

Interactive plots and applications in the browser from Python

Affected versions

Fixed versions

Vulnerability changelog

--------------------
* bugfixes:
- 11422 [component: bokehjs] [BUG] `DeserializationError` when trying to change a `DataTable`'s columns with `CustomJS`
- 11800 [BUG] DeserializationError when plotting graphs
- 11801 [component: bokehjs] [BUG] Log axis figures don't render if they're not visible at start
- 11807 [component: bokehjs] Work around issues with initialization-time change discovery
- 11808 Don't unnecessarily update node/edge renderers in graphs

* tasks:
- 11613 [component: docs] Cache-bust custom.css for docs
- 11791 [component: docs] Update issue template to use new GH forms
- 11761 [component: docs] Clarify use of color in first steps guide
- 11762 [component: docs] Replace slash with backslash for PS commands
- 11767 [component: bokehjs] Upgrade jquery-ui to resolve security concerns
- 11781 [component: examples] fix transform jitter example
- 11786 bokeh 2.4.2 backports
- 11790 [component: build] Bryanv/pin sphinx 42
- 11797 Add OS to bokeh info
- 11805 More 3.0 -> 2.4.2 backports
- 11810 [component: docs] Update docs for new issue forms
- 11824 Updates for release

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.1

CVSS v3 Details

MEDIUM 6.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
CHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
LOW
Availability Availability (A)
NONE

CVSS v2 Details

MEDIUM 4.3
Access Vector (AV)
NETWORK
Access Complexity (AC)
MEDIUM
Authentication (Au)
NONE
Confidentiality Impact (C)
NONE
Integrity Impact (I)
PARTIAL
Availability Impact (A)
NONE