VDB
Sign up
HIGH8.8

PYSEC-2024-173

Quick fix

PYSEC-2024-173 — streampipes: upgrade to the fixed version with the command below.

pip install --upgrade 'streampipes>=0.95.0'

Details

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0.

Users are recommended to upgrade to version 0.95.0, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/streampipes
Introduced in: 0Fixed in: 0.95.0
Fixpip install --upgrade 'streampipes>=0.95.0'

References