PyPi: Dds-Cli

CVE-2022-3102

Transitive

Safety vulnerability ID: 65300

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 18, 2022 Updated at Jun 04, 2024
Scan your Python projects for vulnerabilities →

Advisory

Dds-cli 2.1.0 pins its jwcrypto dependency to version 1.4 from the earlier 1.0, in response to security concerns highlighted by CVE-2022-3102.
https://github.com/ScilifelabDataCentre/dds_cli/pull/537/commits/aae2610d78bf2c2daec94be1172739ad80819779

Affected package

dds-cli

Latest version: 2.7.0

A command line tool to manage data and projects in the SciLifeLab Data Delivery System.

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* Add command for checking for busy projects by valyo in https://github.com/ScilifelabDataCentre/dds_cli/pull/536
* Pin versions and upgrade jwcrypto according to security scan by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/537
* Add tests for maintenance_manager and an error fix by valyo in https://github.com/ScilifelabDataCentre/dds_cli/pull/539
* Inform users of contacting "support" and not "Data Centre" by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/543
* Checksum tests by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/538
* Dds 1360 file encryptor py generate shared key by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/544
* Clarify the CLI installation instructions by valyo in https://github.com/ScilifelabDataCentre/dds_cli/pull/540
* Change message in exception when data already uploaded by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/541
* Print out "[action] cancelled" after KeyboardInterrupt by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/542
* Raise exceptions instead of printing + os exit by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/545
* New release: Hopefully `busy` status fix. by inaod568 in https://github.com/ScilifelabDataCentre/dds_cli/pull/546


**Full Changelog**: https://github.com/ScilifelabDataCentre/dds_cli/compare/v2.0.0...v2.1.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 8.1

CVSS v3 Details

HIGH 8.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
HIGH
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH