Safety vulnerability ID: 70566
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Datacube-ows version 1.8.40 has updated its Pillow dependency to version 10.2.0 to address security concerns outlined in CVE-2023-4863.
Latest version: 1.8.43
Open Data Cube Open Web Services
-------------------
Bug fix release
* Loading now uses `skip_broken_datasets=True` by default. (1001)
* Bump base osgeo/gdal docker image version. (1003)
* Update versions of several upstream packages to avoid known security issues (1004, 1005, 1008)
* pre-commit autoupdate (1006)
* Make S3 URL rewriting work with metadata indexed from STAC (1011)
* Update HISTORY.rst and increment default version for release and some tests. (1013)
This release includes contributions from whatnick, pjonsson, SpacemanPaul, and various automatic updater bots.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application