PyPi: Vermin

CVE-2022-23491

Transitive

Safety vulnerability ID: 59078

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 07, 2022 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Vermin 1.5.2 updates its dependency 'certifi' to version '2022.12.07' to include a security fix.
https://github.com/netromdk/vermin/pull/135/files
https://github.com/advisories/GHSA-43fp-rhv2-5gv8

Affected package

vermin

Latest version: 1.6.0

Concurrently detect the minimum Python versions needed to run code

Affected versions

Fixed versions

Vulnerability changelog

* **Union types (`X | Y`) detection turned into opt-in feature** (176 fixes 103)
* See the [caveats section](https://github.com/netromdk/vermin#caveats) for more information.
* Added missing rules and fixed some existing ones (155 fixes 144)
* Added 120 new rules
* 31 modules
* 68 members
* 21 kwargs
* Fixed 17 rules
* Thanks to cpAdm for reporting the rules issues!
* Fixed error reporting that broke parsable format (156 fixes 150)
* Fixed reported versions for built-in `type()` (172 fixes 171)
* Visit keyword values if not excluded/ignored (173 fixes 168)
* Union types detection also considers attributes (174 fixes 159)
* Improved usage section of README (175 fixes 158)
* Fixed a typo in the `--help` documentation (169, Eutropios)
* [actions] Don't test using EOL Python 3.6 (134)
* Security
* Upgrade certifi to 2022.12.07 (135, GHSA-43fp-rhv2-5gv8)
* Update GitPython to 3.1.30 (157, GHSA-hcpj-qp55-gfph)

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
HIGH
Availability Availability (A)
NONE