PyPi: Vermin

CVE-2022-24439

Transitive

Safety vulnerability ID: 59087

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 06, 2022 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Vermin 1.5.2 updates its dependency 'GitPython' to version '3.1.30' to include a security fix.
https://github.com/netromdk/vermin/pull/157

Affected package

vermin

Latest version: 1.6.0

Concurrently detect the minimum Python versions needed to run code

Affected versions

Fixed versions

Vulnerability changelog

* **Union types (`X | Y`) detection turned into opt-in feature** (176 fixes 103)
* See the [caveats section](https://github.com/netromdk/vermin#caveats) for more information.
* Added missing rules and fixed some existing ones (155 fixes 144)
* Added 120 new rules
* 31 modules
* 68 members
* 21 kwargs
* Fixed 17 rules
* Thanks to cpAdm for reporting the rules issues!
* Fixed error reporting that broke parsable format (156 fixes 150)
* Fixed reported versions for built-in `type()` (172 fixes 171)
* Visit keyword values if not excluded/ignored (173 fixes 168)
* Union types detection also considers attributes (174 fixes 159)
* Improved usage section of README (175 fixes 158)
* Fixed a typo in the `--help` documentation (169, Eutropios)
* [actions] Don't test using EOL Python 3.6 (134)
* Security
* Upgrade certifi to 2022.12.07 (135, GHSA-43fp-rhv2-5gv8)
* Update GitPython to 3.1.30 (157, GHSA-hcpj-qp55-gfph)

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

CRITICAL 9.8

CVSS v3 Details

CRITICAL 9.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH