This repository has been archived by the owner on Feb 8, 2024. It is now read-only.
CVE-2021-34141 (Medium) detected in numpy-1.15.1-cp37-cp37m-manylinux1_x86_64.whl #49
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-34141 - Medium Severity Vulnerability
NumPy is the fundamental package for array computing with Python.
Library home page: https://files.pythonhosted.org/packages/1a/2e/4e298c92b1fced64a4414ada9af3253a91083b92b131c2b10c057c507982/numpy-1.15.1-cp37-cp37m-manylinux1_x86_64.whl
Path to dependency file: /src/pybind/mgr/diskprediction_local/requirements.txt
Path to vulnerable library: /src/pybind/mgr/diskprediction_local/requirements.txt,/src/pybind/rgw,/src/pybind/rbd
Dependency Hierarchy:
Found in HEAD commit: b7c0ec1e6a9bc4b3d908a672c3a8228bdb8dfbd0
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
Publish Date: 2021-12-17
URL: CVE-2021-34141
Base Score Metrics:
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-34141
Release Date: 2021-12-17
Fix Resolution: numpy - 1.22.0rc1,1.12.0b1;numpy-base - 1.16.2;numpy - 1.13.2,1.17.4;albatradis - 1.0.1
The text was updated successfully, but these errors were encountered: