ydata-profiling
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ydata-profilingpage 1 of 1
- CVE-2024-37062HIGHCVSS 7.8EG 7.82024-06-04
vulnerable: 4.0.0 ... 4.8.3 (19 versions)
Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user's system when loaded.
- CVE-2024-37063HIGHCVSS 7.8EG 7.82024-06-04
vulnerable: 4.0.0 ... 4.8.3 (19 versions)
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.
- CVE-2024-37064HIGHCVSS 7.8EG 7.82024-06-04
vulnerable: 4.0.0 ... 4.8.3 (19 versions)
Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code on an end user's system when loaded.
Check whether ydata-profiling is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ydata-profiling CVEs against the assets you own.
Start Free Scan →