PyPi: Sw360

CVE-2024-3651

Transitive

Safety vulnerability ID: 68051

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Apr 14, 2024 Updated at Apr 22, 2024
Scan your Python projects for vulnerabilities →

Advisory

Sw360 version 1.5.0 has updated its dependency on the idna library to version 3.7 in order to address the security vulnerabilities detailed in CVE-2024-3651.

Affected package

sw360

Latest version: 1.5.0

Python interface to the SW360 software component catalogue

Affected versions

Fixed versions

Vulnerability changelog

* when using CaPyCLI in a CI pipeline, connection problems to teh SW360 server (5xx) cause
the pipeline to fail. We have now add an improved session handling to all api requests.
* dependency updates due to security vulnerabilities in idna.

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application