Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix 6 vulnerable dependencies identified by Prisma Cloud #7

Closed
wants to merge 1 commit into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions sca-package/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
<dependency>
<groupId>org.apache.httpcomponents</groupId>
<artifactId>httpclient</artifactId>
<version>4.3.2</version>
<version>5.0.3</version>
<type>jar</type>
<scope>compile</scope>
</dependency>
Expand All @@ -29,12 +29,12 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-core</artifactId>
<version>2.4.0</version>
<version>2.15.0</version>
</dependency>
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.4.0</version>
<version>2.16.0</version>
</dependency>
</dependencies>
<build>
Expand Down
6 changes: 3 additions & 3 deletions sca-package/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
django==1.2
flask==0.6
requests==2.26.0
django == 3.2.4
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

django 3.2.4 / requirements.txt

Total vulnerabilities: 19

Critical: 5 High: 12 Medium: 2 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-31047 CRITICAL CRITICAL 9.8 3.2.19 Open
CVE-2022-34265 CRITICAL CRITICAL 9.8 3.2.14 Open
CVE-2022-28347 CRITICAL CRITICAL 9.8 3.2.13 Open
CVE-2022-28346 CRITICAL CRITICAL 9.8 3.2.13 Open
CVE-2021-35042 CRITICAL CRITICAL 9.8 3.2.5 Open
CVE-2021-44420 HIGH HIGH 7.3 3.2.10 Open
CVE-2023-36053 HIGH HIGH 7.5 3.2.20 Open
CVE-2023-24580 HIGH HIGH 7.5 3.2.18 Open
CVE-2023-23969 HIGH HIGH 7.5 3.2.17 Open
CVE-2022-41323 HIGH HIGH 7.5 3.2.16 Open
CVE-2022-36359 HIGH HIGH 8.8 3.2.15 Open
CVE-2022-23833 HIGH HIGH 7.5 3.2.12 Open
CVE-2021-45115 HIGH HIGH 7.5 3.2.11 Open
CVE-2021-45116 HIGH HIGH 7.5 3.2.11 Open
CVE-2023-46695 HIGH HIGH 7.5 3.2.23 Open
CVE-2023-43665 HIGH HIGH 7.5 3.2.22 Open
CVE-2023-41164 HIGH HIGH 7.5 3.2.21 Open
CVE-2022-22818 MEDIUM MEDIUM 6.1 3.2.12 Open
CVE-2021-45452 MEDIUM MEDIUM 5.3 3.2.11 Open

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

django 3.2.4 / requirements.txt

Total vulnerabilities: 19

Critical: 5 High: 12 Medium: 2 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-35042 CRITICAL CRITICAL 9.8 3.2.5 Open
CVE-2023-31047 CRITICAL CRITICAL 9.8 3.2.19 Open
CVE-2022-34265 CRITICAL CRITICAL 9.8 3.2.14 Open
CVE-2022-28347 CRITICAL CRITICAL 9.8 3.2.13 Open
CVE-2022-28346 CRITICAL CRITICAL 9.8 3.2.13 Open
CVE-2023-36053 HIGH HIGH 7.5 3.2.20 Open
CVE-2021-44420 HIGH HIGH 7.3 3.2.10 Open
CVE-2023-24580 HIGH HIGH 7.5 3.2.18 Open
CVE-2023-23969 HIGH HIGH 7.5 3.2.17 Open
CVE-2022-41323 HIGH HIGH 7.5 3.2.16 Open
CVE-2022-36359 HIGH HIGH 8.8 3.2.15 Open
CVE-2022-23833 HIGH HIGH 7.5 3.2.12 Open
CVE-2021-45115 HIGH HIGH 7.5 3.2.11 Open
CVE-2021-45116 HIGH HIGH 7.5 3.2.11 Open
CVE-2023-46695 HIGH HIGH 7.5 3.2.23 Open
CVE-2023-41164 HIGH HIGH 7.5 3.2.21 Open
CVE-2023-43665 HIGH HIGH 7.5 3.2.22 Open
CVE-2022-22818 MEDIUM MEDIUM 6.1 3.2.12 Open
CVE-2021-45452 MEDIUM MEDIUM 5.3 3.2.11 Open

flask == 2.3.2
requests == 2.31.0