This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2025-04-16 07:28:19 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
---|---|
c3fb48cc-a2ff-11ed-8fbc-6cf0490a8c18 | Spotipy -- Path traversal vulnerability StÃÂéphane Bruckert
Discovery 2023-01-16 Entry 2023-02-02 py37-spotipy py38-spotipy py39-spotipy py310-spotipy py311-spotipy <= 2.22.0 CVE-2023-23608 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23608 https://github.com/spotipy-dev/spotipy/security/advisories/GHSA-q764-g6fm-555v |
475d1968-f99d-11ef-b382-b0416f0c4c67 | Spotipy -- Spotipy's cache file, containing spotify auth token, is created with overly broad permissions security-advisories@github.com reports:
Discovery 2025-02-27 Entry 2025-03-05 py38-spotipy py39-spotipy py310-spotipy py311-spotipy < 2.25.1 CVE-2025-27154 https://nvd.nist.gov/vuln/detail/CVE-2025-27154 |