PYSEC-2023-64

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/mage-ai/PYSEC-2023-64.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2023-64
Aliases
Published
2023-05-09T15:15:00Z
Modified
2023-11-01T05:01:59.996248Z
Summary
[none]
Details

mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by users who are not signed in or do not have editor permissions. Version 0.8.72 contains a fix for this issue.

References

Affected packages

PyPI / mage-ai

Package

Affected ranges

Type
GIT
Repo
https://github.com/mage-ai/mage-ai
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0.8.34
Fixed
0.8.72

Affected versions

0.*

0.8.34
0.8.35
0.8.36
0.8.37
0.8.38
0.8.39
0.8.40
0.8.41
0.8.42
0.8.43
0.8.44
0.8.45
0.8.46
0.8.47
0.8.48
0.8.49
0.8.50
0.8.51
0.8.52
0.8.53
0.8.54
0.8.55
0.8.56
0.8.57
0.8.58
0.8.59
0.8.60
0.8.61
0.8.62
0.8.63
0.8.64
0.8.66
0.8.67
0.8.68
0.8.69
0.8.70
0.8.71