Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Known security vulnerabilities detected #22

Open
icorgadmin opened this issue Jun 5, 2020 · 0 comments
Open

Known security vulnerabilities detected #22

icorgadmin opened this issue Jun 5, 2020 · 0 comments

Comments

@icorgadmin
Copy link

Known security vulnerabilities detected

Dependency pycrypto Version <= 2.6.1
Defined in requirements.txt
Vulnerabilities
CVE-2018-6594 Moderate severity
CVE-2013-7459 Moderate severity

Dependency Pillow Version < 3.1.1 Upgrade to ~> 3.1.1
Defined in requirements.txt
Vulnerabilities
CVE-2016-4009 High severity
CVE-2016-0740 Moderate severity
CVE-2016-9189 Moderate severity
CVE-2016-2533 Moderate severity
CVE-2016-0775 Moderate severity
View 2 more [https://github.com/ImperialCollegeLondon/citizengrid/network/alert/dashboard/requirements.txt/Pillow/open]

Dependency org.apache.httpcomponents:httpclient Version < 4.3.6 Upgrade to ~> 4.3.6
Defined in pom.xml
Vulnerabilities
CVE-2015-5262 Moderate severity

Dependency djangorestframework Version < 3.9.1 Upgrade to ~> 3.9.1
Defined in requirements.txt
Vulnerabilities
WS-2019-0037 Moderate severity

Dependency pillow Version < 6.2.0 Upgrade to ~> 6.2.0
Defined in requirements.txt
Vulnerabilities
CVE-2019-16865 Low severity

Review all vulnerable dependencies [https://github.com/ImperialCollegeLondon/citizengrid/network/alerts]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant