PyPi: Parsons

CVE-2022-21797

Transitive

Safety vulnerability ID: 59056

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 26, 2022 Updated at Mar 05, 2024
Scan your Python projects for vulnerabilities →

Advisory

Parsons 1.0.0 updates its dependency 'joblib' to v1.2.0 to include a security fix.
https://github.com/move-coop/parsons/pull/764/commits/ad3c0ecd431ac9b3617196d397f9e4b8f6643d7e

Affected package

parsons

Latest version: 3.1.0

Affected versions

Fixed versions

Vulnerability changelog

New Connectors
* feat: scytl connector by agreenspan24 in https://github.com/move-coop/parsons/pull/737
* Donorbox connector by shaunagm in https://github.com/move-coop/parsons/pull/773
New Features
* Add use_env_token option to S3 object by sjwmoveon in https://github.com/move-coop/parsons/pull/745
* Updates to ActionKit, Braintree, and S3 connectors by crayolakat in https://github.com/move-coop/parsons/pull/754
* Add get_aliases() function to Google Admin connector by crayolakat in https://github.com/move-coop/parsons/pull/769
* merge contacts and test by mkwoods927 in https://github.com/move-coop/parsons/pull/776
* Add printed list functionality to VAN connector by sharinef1 in https://github.com/move-coop/parsons/pull/778
* Updates to ActionKit, S3, and NGPVan by crayolakat in https://github.com/move-coop/parsons/pull/775
* Opt out phones in EA use case and sample script by mkwoods927 in https://github.com/move-coop/parsons/pull/670
Automated Testing
* Unit tests for 685 by alxmrs in https://github.com/move-coop/parsons/pull/746
* Update cache keys for CircleCI configuration by SorenSpicknall in https://github.com/move-coop/parsons/pull/752
* Update CircleCI Docs key fingerprint by neverett in https://github.com/move-coop/parsons/pull/785
Bug Fixes
* Fix assert_matching_tables by crayolakat in https://github.com/move-coop/parsons/pull/759
* Scytl fix browser headers and requests lib w mock by agreenspan24 in https://github.com/move-coop/parsons/pull/762
* GitHub Connector Fix by SorenSpicknall in https://github.com/move-coop/parsons/pull/767
* NGPVAN: Saved List Overwrite Bug Fix by jburchard in https://github.com/move-coop/parsons/pull/770
* Upgrade dependencies by crayolakat in https://github.com/move-coop/parsons/pull/779
* Change release version to 1.0 by Jason94 in https://github.com/move-coop/parsons/pull/793
* Fix 780 and 781 - Google Sheets documentation by ethyoo in https://github.com/move-coop/parsons/pull/786
Documentation
* Typo fixes for ETL best practices guide. by alxmrs in https://github.com/move-coop/parsons/pull/747
* Fix 707 - Parsing of code blocks for Mobilize America documentation by ethyoo in https://github.com/move-coop/parsons/pull/749
* Simple docs for the SMTP connector by AndrewRook in https://github.com/move-coop/parsons/pull/735
* Update Code of Conduct contact email by shaunagm in https://github.com/move-coop/parsons/pull/756
* Update requirements.txt for joblib security vulnerability by SorenSpicknall in https://github.com/move-coop/parsons/pull/764
* Add docker image references, logo, scytl connector in sidebar by shaunagm in https://github.com/move-coop/parsons/pull/782

New Contributors
* alxmrs made their first contribution in https://github.com/move-coop/parsons/pull/747
* ethyoo made their first contribution in https://github.com/move-coop/parsons/pull/749
* agreenspan24 made their first contribution in https://github.com/move-coop/parsons/pull/737
* sharinef1 made their first contribution in https://github.com/move-coop/parsons/pull/778

**Full Changelog**: https://github.com/move-coop/parsons/compare/v0.21.0...v1.0.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH