PyPi: Juicenet-Cli

CVE-2024-22195

Transitive

Safety vulnerability ID: 64586

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jan 11, 2024 Updated at Oct 11, 2024
Scan your Python projects for vulnerabilities →

Advisory

Juicenet-cli version 0.32.0 resolves CVE-2024-22195 by upgrading its jinja2 dependency from version 3.1.2 to 3.1.3.
https://github.com/Ravencentric/juicenet-cli/commit/6e64a808e7f132c45202028b1b5d29d761ebb6d6

Affected package

juicenet-cli

Latest version: 0.46.1

CLI tool designed to simplify the process of uploading files to Usenet

Affected versions

Fixed versions

Vulnerability changelog

- **deps:** Update minor deps ([ad90e1c](https://github.com/Ravencentric/juicenet-cli/commit/ad90e1c215acbfadfb6fd898bac480087d6be54a)) - (Raventric)
- **deps:** Update dependency cyclopts to v2.2.0 ([53](https://github.com/Ravencentric/juicenet-cli/issues/53)) ([9674899](https://github.com/Ravencentric/juicenet-cli/commit/9674899401ad6d688d02b29194c3a4ff00b6100e)) - (renovate[bot])
- **deps:** Update peter-evans/dockerhub-description action to v4 ([52](https://github.com/Ravencentric/juicenet-cli/issues/52)) ([17e9b62](https://github.com/Ravencentric/juicenet-cli/commit/17e9b6275fef69759d59e3cd15aeadd63689a427)) - (renovate[bot])
- **deps:** Update dependency pydantic-core to v2.16.1 ([50](https://github.com/Ravencentric/juicenet-cli/issues/50)) ([0ef0a25](https://github.com/Ravencentric/juicenet-cli/commit/0ef0a259a6b2397009c6933838e859f554cec99e)) - (renovate[bot])
- **deps:** Update all non-major dependencies ([49](https://github.com/Ravencentric/juicenet-cli/issues/49)) ([b1ccc4a](https://github.com/Ravencentric/juicenet-cli/commit/b1ccc4ac2306e1f8e1f0692135ff69638f9c482b)) - (renovate[bot])
- **deps:** Update actions/cache action to v4 ([47](https://github.com/Ravencentric/juicenet-cli/issues/47)) ([4df6b4d](https://github.com/Ravencentric/juicenet-cli/commit/4df6b4d1e247b1e64e0189c76e03069bb586a3a5)) - (renovate[bot])
- **deps:** Update all non-major dependencies ([48](https://github.com/Ravencentric/juicenet-cli/issues/48)) ([2e19953](https://github.com/Ravencentric/juicenet-cli/commit/2e1995380d3a2364a1cd58bd8d5f37a76f19406b)) - (renovate[bot])
- **deps:** Update dependency cyclopts to v2.1.0 ([45](https://github.com/Ravencentric/juicenet-cli/issues/45)) ([6475785](https://github.com/Ravencentric/juicenet-cli/commit/64757852bcbe782c22ebdfe57069e5d75e6b5585)) - (renovate[bot])
- **deps:** Update dependency mkdocs-material to v9.5.4 ([43](https://github.com/Ravencentric/juicenet-cli/issues/43)) ([904aa1f](https://github.com/Ravencentric/juicenet-cli/commit/904aa1f2a5121df1d2d9bfc327733fa03d94c8e0)) - (renovate[bot])
- **deps-dev:** Bump jinja2 from 3.1.2 to 3.1.3 ([41](https://github.com/Ravencentric/juicenet-cli/issues/41)) ([3bd7dfc](https://github.com/Ravencentric/juicenet-cli/commit/3bd7dfc5bd4ac7d25c7ce8abffe4ae481416d170)) - (dependabot[bot])
- **deps:** Update dependency ruff to v0.1.13 ([39](https://github.com/Ravencentric/juicenet-cli/issues/39)) ([c5f3a5d](https://github.com/Ravencentric/juicenet-cli/commit/c5f3a5d47d1a6d4f843ca122415b27cf6ac8c9d2)) - (renovate[bot])
- **deps:** Update dependency jinja2 to v3.1.3 [security] ([38](https://github.com/Ravencentric/juicenet-cli/issues/38)) ([6e64a80](https://github.com/Ravencentric/juicenet-cli/commit/6e64a808e7f132c45202028b1b5d29d761ebb6d6)) - (renovate[bot])
- **deps:** Update all non-major dependencies ([36](https://github.com/Ravencentric/juicenet-cli/issues/36)) ([428720d](https://github.com/Ravencentric/juicenet-cli/commit/428720d5cbcb1698553f91de379b0e2fdf0835b7)) - (renovate[bot])

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.1

CVSS v3 Details

MEDIUM 6.1
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
REQUIRED
Scope (S)
CHANGED
Confidentiality Impact (C)
LOW
Integrity Impact (I)
LOW
Availability Availability (A)
NONE