PyPi: Nucliadb

CVE-2023-4807

Transitive

Safety vulnerability ID: 65864

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 08, 2023 Updated at Jun 13, 2024
Scan your Python projects for vulnerabilities →

Advisory

Nucliadb 2.44.1 updates its cryptography dependency from 42.0.2 to 42.0.4 due to the CVE-2023-4807.
https://github.com/nuclia/nucliadb/pull/1881/commits/bd2366f23f0388d1b02ced16b25e473ecf73744a

Affected package

nucliadb

Latest version: 4.0.3.post603

None

Affected versions

Fixed versions

Vulnerability changelog

What's Changed


* Better handle resumable uri not found errors on tus patch by lferran in https://github.com/nuclia/nucliadb/pull/1887
* Bump dependencies to fix vulnerabilities by lferran in https://github.com/nuclia/nucliadb/pull/1881
* Collect learning id on chat audit by lferran in https://github.com/nuclia/nucliadb/pull/1890
* Remove Unimplemented facets feature from find endpoints by lferran in https://github.com/nuclia/nucliadb/pull/1882
* merge on commit by hermeGarcia in https://github.com/nuclia/nucliadb/pull/1896
* Add shards and node info on catalog response by lferran in https://github.com/nuclia/nucliadb/pull/1895
* Place new shards on nodes based on disk space available by lferran in https://github.com/nuclia/nucliadb/pull/1891
* remove fst by hermeGarcia in https://github.com/nuclia/nucliadb/pull/1869
* Add generative_model in chat request by lferran in https://github.com/nuclia/nucliadb/pull/1866
* remove async merge by hermeGarcia in https://github.com/nuclia/nucliadb/pull/1898
* Handle shard not found errors while indexing by lferran in https://github.com/nuclia/nucliadb/pull/1900
* fix stack rebuild by hermeGarcia in https://github.com/nuclia/nucliadb/pull/1903
* Parallelize KB migrations by lferran in https://github.com/nuclia/nucliadb/pull/1905
* Handle more shard not found node errors by lferran in https://github.com/nuclia/nucliadb/pull/1902
* Whitelist proxied headers when proxing to learning services by lferran in https://github.com/nuclia/nucliadb/pull/1909


**Full Changelog**: https://github.com/nuclia/nucliadb/compare/v2.44.0...v2.44.1

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.8

CVSS v3 Details

HIGH 7.8
Attack Vector (AV)
LOCAL
Attack Complexity (AC)
LOW
Privileges Required (PR)
LOW
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH