PyPI package
scancodeio
pkg:pypi/scancodeio
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-40024 | — | < 32.5.2 | 32.5.2 | Aug 14, 2023 | ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a | ||
| CVE-2023-39523 | — | < 32.5.1 | 32.5.1 | Aug 7, 2023 | ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append malicious commands in the `docker_referenc |
- CVE-2023-40024Aug 14, 2023affected < 32.5.2fixed 32.5.2
ScanCode.io is a server to script and automate software composition analysis pipelines. In the `/license/` endpoint, the detailed view key is not properly validated and sanitized, which can result in a potential cross-site scripting (XSS) vulnerability when attempting to access a
- CVE-2023-39523Aug 7, 2023affected < 32.5.1fixed 32.5.1
ScanCode.io is a server to script and automate software composition analysis with ScanPipe pipelines. Prior to version 32.5.1, the software has a possible command injection vulnerability in the docker fetch process as it allows to append malicious commands in the `docker_referenc