[Snyk] Security upgrade urllib3 from 1.26.20 to 2.5.0 #21
An automation triggered a pipeline warning
Found 69 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.
Output from Automations
4 rules were checked:
If a new dependency is added where the license risk is at least medium
then notify all users in the group admins by email
✔️ The rule did not trigger. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before
then notify all users in the group admins by email
✔️ The rule did not trigger. Manage rule
If there is a dependency where the license risk is at least high
then send a pipeline warning
✔️ The rule did not trigger. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected
then send a pipeline warning
| Vulnerability | CVSS2 | CVSS3 | Dependency | Dependency Licenses |
|---|---|---|---|---|
| CVE-2023-47248 | N/A | 9.8 | pyarrow (pip) | Unknown License |
| CVE-2024-52338 | N/A | 9.8 | pyarrow (pip) | Unknown License |
| CVE-2020-13091 | 7.5 | 9.8 | pandas (pip) | Apache-2.0, BSD-2-Clause, BSD-3-Clause, MIT, Python-2.0, Python-2.0.1, TCL, Unknown License |
| CVE-2021-34552 | 7.5 | 9.8 | pillow (pip) | HPND |
| CVE-2022-22817 | 7.5 | 9.8 | pillow (pip) | HPND |
| CVE-2020-13092 | 7.5 | 9.8 | scikit-learn (pip) | Unknown License |
| CVE-2018-18074 | 5 | 9.8 | requests (pip) | Apache-2.0, Unknown License |
| CVE-2019-6446 | 7.5 | 9.8 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2021-32797 | 6.8 | 9.6 | notebook (pip) | Unknown License |
| CVE-2021-32798 | 6.8 | 9.6 | notebook (pip) | Unknown License |
| CVE-2022-24303 | 6.4 | 9.1 | pillow (pip) | HPND |
| CVE-2023-50447 | N/A | 8.1 | pillow (pip) | HPND |
| CVE-2018-8768 | 6.8 | 7.8 | notebook (pip) | Unknown License |
| CVE-2022-45198 | N/A | 7.5 | pillow (pip) | HPND |
| CVE-2019-12410 | 5 | 7.5 | pyarrow (pip) | Unknown License |
| CVE-2020-28975 | 5 | 7.5 | scikit-learn (pip) | Unknown License |
| CVE-2021-23437 | 5 | 7.5 | pillow (pip) | HPND |
| CVE-2024-27454 | N/A | 7.5 | orjson (pip) | Apache-2.0, MIT, Unknown License |
| PYSEC-0000-CVE-2022-24758 | 5 | 7.5 | notebook (pip) | Unknown License |
| CVE-2024-3651 | N/A | 7.5 | idna (pip) | BSD-3-Clause |
| CVE-2023-44271 | N/A | 7.5 | pillow (pip) | HPND |
| CVE-2022-24758 | 5 | 7.5 | notebook (pip) | Unknown License |
| CVE-2019-18874 | 5 | 7.5 | psutil (pip) | BSD-2-Clause, BSD-3-Clause, Unknown License |
| CVE-2022-42969 | N/A | 7.5 | py (pip) | MIT |
| CVE-2017-12852 | 5 | 7.5 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2019-12408 | 5 | 7.5 | pyarrow (pip) | Unknown License |
| CVE-2015-2296 | 6.8 | N/A | requests (pip) | Apache-2.0, Unknown License |
| CVE-2015-7337 | 6.8 | N/A | notebook (pip) | Unknown License |
| CVE-2024-28219 | N/A | 6.7 | pillow (pip) | HPND |
| CVE-2024-22421 | N/A | 6.5 | notebook (pip) | Unknown License |
| CVE-2022-22815 | 6.4 | 6.5 | pillow (pip) | HPND |
| CVE-2018-20349 | 4.3 | 6.5 | igraph (pip) | Unknown License |
| CVE-2022-22816 | 6.4 | 6.5 | pillow (pip) | HPND |
| CVE-2018-19352 | 4.3 | 6.1 | notebook (pip) | Unknown License |
| CVE-2019-10255 | 5.8 | 6.1 | notebook (pip) | Unknown License |
| CVE-2018-19351 | 4.3 | 6.1 | notebook (pip) | Unknown License |
| CVE-2024-43805 | N/A | 6.1 | notebook (pip) | Unknown License |
| CVE-2024-22420 | N/A | 6.1 | notebook (pip) | Unknown License |
| CVE-2020-26215 | 5.8 | 6.1 | notebook (pip) | Unknown License |
| CVE-2019-10856 | 5.8 | 6.1 | notebook (pip) | Unknown License |
| CVE-2023-32681 | N/A | 6.1 | requests (pip) | Apache-2.0, Unknown License |
| CVE-2024-35195 | N/A | 5.6 | requests (pip) | Apache-2.0, Unknown License |
| CVE-2021-41496 | 2.1 | 5.5 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2014-1858 | 2.1 | 5.5 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2014-1859 | 2.1 | 5.5 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2021-32862 | N/A | 5.4 | nbconvert (pip) | BSD-3-Clause |
| CVE-2019-9644 | 4.3 | 5.4 | notebook (pip) | Unknown License |
| CVE-2021-34141 | 5 | 5.3 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2021-41495 | 3.5 | 5.3 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2024-47081 | N/A | 5.3 | requests (pip) | Apache-2.0, Unknown License |
| CVE-2018-21030 | 5 | 5.3 | notebook (pip) | Unknown License |
| CVE-2025-50181 | N/A | 5.3 | urllib3 (pip) | MIT |
| CVE-2021-33430 | 3.5 | 5.3 | numpy (pip) | BSD-3-Clause, BSD-3-Clause-Open-MPI, GPL-3.0-only, GPL-3.0-or-later, MIT, Unknown License, Zlib |
| CVE-2014-1830 | 5 | N/A | requests (pip) | Apache-2.0, Unknown License |
| CVE-2014-1829 | 5 | N/A | requests (pip) | Apache-2.0, Unknown License |
| CVE-2024-5206 | N/A | 4.7 | scikit-learn (pip) | Unknown License |
| CVE-2024-55565 | N/A | 4.3 | nanoid (npm) | MIT |
| CVE-2015-6938 | 4.3 | N/A | notebook (pip) | Unknown License |
| CVE-2013-2099 | 4.3 | N/A | requests (pip) | Apache-2.0, Unknown License |
| CVE-2022-29238 | 4 | 4.3 | notebook (pip) | Unknown License |
| CVE-2025-5889 | 2.1 | 3.1 | brace-expansion (npm) | MIT |
| debricked-234923 | N/A | N/A | requests (pip) | Apache-2.0, Unknown License |
| debricked-286515 | N/A | N/A | esbuild (npm) | MIT |
| debricked-234843 | N/A | N/A | pillow (pip) | HPND |
| debricked-234825 | N/A | N/A | nbconvert (pip) | BSD-3-Clause |
| debricked-234845 | N/A | N/A | pillow (pip) | HPND |
| debricked-234929 | N/A | N/A | notebook (pip) | Unknown License |
| debricked-184644 | N/A | N/A | pillow (pip) | HPND |
| debricked-229743 | N/A | N/A | pillow (pip) | HPND |