Safety vulnerability ID: 64134
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Rucio 1.26.12 updates its dependency on Paramiko to version 2.10.3 from the earlier 2.7.2, in response to the security vulnerability identified as CVE-2022-24302.
Latest version: 36.0.0
Rucio Package
General
Enhancements
- Release management: Update paramiko dependency due to security advisory 5412
- Release management: Pin the `werkzeug` package version prior to 2.1.0 in Flask 1.1.2 versions 5419
- Replicas: geoip database is always downloaded, even if no URL configured/License key given 5233
- Testing: Print the integration test server logs in the actions 5253
Bugs
- Jinja2 3.1.0 is incompatible with Flask 1.1.2 5398
- Release management: Flask fails after itsdangerous module’s update 5258
- Testing: test_upload_download of test-server fails 5023
- Testing: `common/test_rucio_server` file path bug 5037
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application