PyPi: Ibm-Generative-Ai

CVE-2023-2251

Transitive

Safety vulnerability ID: 65524

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Apr 24, 2023 Updated at May 28, 2024
Scan your Python projects for vulnerabilities →

Advisory

Ibm-generative-ai version 1.0.1 has upgraded its yaml dependency to "^2.3.0" from the prior "^2.2.2" to address the security issue identified as CVE-2023-2251.

Affected package

ibm-generative-ai

Latest version: 3.0.0

IBM Generative AI is a Python library built on IBM's large language model REST interface.

Affected versions

Fixed versions

Vulnerability changelog

What's Changed
* chore(workflows): change test matrix and remove unnecessary build by pilartomas in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/6
* chore(dependency): upgrade yaml dependency due to found vulnerability by pilartomas in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/7
* chore(docs): remove slack application info by pilartomas in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/8
* chore(tests): migrate selected e2e test to integration by pilartomas in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/11
* feat(client): add callback support for all methods by Tomas2D in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/9
* fix(timeout): handle negative timeouts by Tomas2D in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/13
* feat(release): v1.0.1 by pilartomas in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/14

New Contributors
* Tomas2D made their first contribution in https://github.com/IBM/ibm-generative-ai-node-sdk/pull/9

**Full Changelog**: https://github.com/IBM/ibm-generative-ai-node-sdk/compare/v1.0.0...v1.0.1

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
NONE
Availability Availability (A)
HIGH