Skip to content

[Snyk] Security upgrade urllib3 from 2.0.7 to 2.5.0 - #155

Open
Jsn2win wants to merge 1 commit into
masterfrom
snyk-fix-b66eb22a8fee00af2cc737297020a8a7
Open

[Snyk] Security upgrade urllib3 from 2.0.7 to 2.5.0#155
Jsn2win wants to merge 1 commit into
masterfrom
snyk-fix-b66eb22a8fee00af2cc737297020a8a7

fix: extraPackages/pyzmq-17.1.2/docs/requirements.txt to reduce vulne…

d571986
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
Mend Bolt for GitHub / WhiteSource Security Check failed Jun 20, 2025 in 14m 5s

Security Report

You have successfully remediated 102 vulnerabilities, but introduced 55 new vulnerabilities in this branch.

❌ New vulnerabilities:

Partial results (20 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.


Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2022-22817

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl None
CVE-2021-34552

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow-8.3.0 None
CVE-2021-25289

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: 8.1.1 None
CVE-2021-20236

Vulnerable Source Files:

❌ /extraPackages/pyzmq-17.1.2/bundled/zeromq/src/generic_mtrie_impl.hpp

Critical 9.8 libzmqv4.2.5 Upgrade to version: v4.3.3 None
CVE-2020-5312

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 6.2.2 None
CVE-2020-5311

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 6.2.2 None
CVE-2022-24303

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.1 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 9.0.1 None
CVE-2021-25288

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.1 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 8.2.0 None
CVE-2021-25287

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

Critical 9.1 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 8.2.0 None
CVE-2020-5310

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 8.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 6.2.2 None
CVE-2020-35654

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 8.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: 8.1.0 None
CVE-2019-6250

Vulnerable Source Files:

❌ /extraPackages/pyzmq-17.1.2/bundled/zeromq/src/v2_decoder.cpp

High 8.8 libzmqv4.2.5 Upgrade to version: v4.3.1 None
CVE-2023-50447

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 8.1 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: pillow - 10.2.0 None
CVE-2021-20235

Vulnerable Source Files:

❌ /extraPackages/pyzmq-17.1.2/bundled/zeromq/src/decoder_allocators.hpp

High 8.1 libzmqv4.2.5 Upgrade to version: v4.3.3 None
CVE-2020-11538

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 8.1 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: 7.1.0 None
CVE-2020-10379

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 7.8 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: 7.1.0 None
WS-2022-0097

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 7.5 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl None
CVE-2023-44271

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 7.5 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 10.0.0 None
CVE-2022-45199

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 7.5 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 9.3.0 None
CVE-2022-45198

Path to dependency file: /extraPackages/numpy-1.16.0

Path to vulnerable library: /tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip,/tmp/ws-ua_20250620083118_ZONFCU/python_YWDLTF/20250620083153/Pillow-6.0.0.zip

Dependency Hierarchy:

-> ❌ Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl (Vulnerable Library)

High 7.5 Pillow-6.0.0-cp27-cp27m-macosx_10_6_intel.macosx_10_9_intel.macosx_10_9_x86_64.macosx_10_10_intel.macosx_10_10_x86_64.whl Upgrade to version: Pillow - 9.2.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2014-7203 python3_ios-v1.0
CVE-2021-20237 python3_ios-v1.0
WS-2019-0032 js-yaml-2.0.5.tgz
CVE-2016-10540 minimatch-2.0.10.tgz
CVE-2015-9251 jquery-1.12.4.js
CVE-2022-22815 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2023-43804 urllib3-1.26.5-py2.py3-none-any.whl
CVE-2021-23358 underscore-1.7.0.tgz
CVE-2022-24303 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2018-3721 lodash-3.10.1.tgz
CVE-2020-7792 mout-0.11.1.tgz
CVE-2023-50447 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2020-11023 jquery-1.12.4.js
CVE-2022-21213 mout-0.11.1.tgz
CVE-2024-56326 Jinja2-3.0.1-py3-none-any.whl
CVE-2021-3820 i-0.3.6.tgz
CVE-2023-32681 requests-2.25.1-py2.py3-none-any.whl
CVE-2016-10540 minimatch-0.2.14.tgz
CVE-2022-3517 minimatch-2.0.10.tgz
CVE-2021-23337 lodash-0.9.2.tgz
CVE-2021-43138 async-0.1.9.js
CVE-2023-28155 request-2.12.0.tgz
CVE-2025-5889 brace-expansion-1.1.11.tgz
CVE-2021-3918 json-schema-0.2.3.tgz
CVE-2022-24999 qs-6.5.2.tgz
CVE-2018-16487 lodash-0.9.2.tgz
CVE-2019-6250 python3_ios-v1.0
CVE-2022-1537 grunt-0.4.5.tgz
CVE-2020-28500 lodash-3.10.1.tgz
CVE-2024-37891 urllib3-1.26.5-py2.py3-none-any.whl
CVE-2022-3517 minimatch-0.3.0.tgz
CVE-2022-25883 semver-5.7.1.tgz
CVE-2020-11023 jquery-1.8.1.min.js
CVE-2022-3517 minimatch-0.2.14.tgz
CVE-2019-1010266 lodash-2.4.2.tgz
CVE-2025-27516 Jinja2-3.0.1-py3-none-any.whl
CVE-2022-22816 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2020-28282 getobject-0.1.0.tgz
CVE-2024-35195 requests-2.25.1-py2.py3-none-any.whl
CVE-2022-45198 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2023-44271 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
WS-2019-0063 js-yaml-2.0.5.tgz
CVE-2022-0436 grunt-0.4.5.tgz
CVE-2020-7751 pathval-0.1.1.tgz
CVE-2020-11022 jquery-1.8.1.min.js
CVE-2020-8203 lodash-0.9.2.tgz
CVE-2021-23437 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2018-16487 lodash-2.4.2.tgz
CVE-2019-10744 lodash-3.10.1.tgz
CVE-2021-44906 minimist-1.2.5.tgz
CVE-2021-34141 numpy-1.20.3-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl
CVE-2021-34552 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2020-15166 python3_ios-v1.0
CVE-2020-28500 lodash-2.4.2.tgz
CVE-2019-1010266 lodash-3.10.1.tgz
CVE-2024-56201 Jinja2-3.0.1-py3-none-any.whl
CVE-2024-39689 certifi-2021.5.30-py2.py3-none-any.whl
CVE-2024-34064 Jinja2-3.0.1-py3-none-any.whl
CVE-2021-20236 python3_ios-v1.0
CVE-2023-37920 certifi-2021.5.30-py2.py3-none-any.whl
WS-2018-0625 xmlbuilder-2.6.5.tgz
CVE-2021-23337 lodash-3.10.1.tgz
CVE-2017-16138 mime-1.2.7.tgz
WS-2018-0148 utile-0.2.1.tgz
CVE-2022-22817 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2016-10540 minimatch-0.3.0.tgz
CVE-2020-7729 grunt-0.4.5.tgz
CVE-2017-16026 request-2.12.0.tgz
CVE-2022-45199 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2012-6708 jquery-1.8.1.min.js
CVE-2024-47081 requests-2.25.1-py2.py3-none-any.whl
CVE-2020-7656 jquery-1.8.1.min.js
CVE-2020-8203 lodash-2.4.2.tgz
CVE-2014-7202 python3_ios-v1.0
CVE-2021-20234 python3_ios-v1.0
CVE-2019-10744 lodash-0.9.2.tgz
CVE-2023-26136 tough-cookie-2.5.0.tgz
CVE-2021-23337 lodash-2.4.2.tgz
CVE-2019-1010266 lodash-0.9.2.tgz
WS-2022-0097 Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
CVE-2024-3651 idna-2.10-py2.py3-none-any.whl
CVE-2024-6345 setuptools-57.0.0-py3-none-any.whl
CVE-2022-46175 json5-0.4.0.tgz
CVE-2018-3721 lodash-0.9.2.tgz
CVE-2018-16487 lodash-3.10.1.tgz
CVE-2024-57065 utile-0.2.1.tgz
CVE-2023-45803 urllib3-1.26.5-py2.py3-none-any.whl
CVE-2021-20235 python3_ios-v1.0
CVE-2020-8203 lodash-3.10.1.tgz
CVE-2020-11022 jquery-1.12.4.js
CVE-2025-47273 setuptools-57.0.0-py3-none-any.whl
CVE-2022-40897 setuptools-57.0.0-py3-none-any.whl
CVE-2018-3721 lodash-2.4.2.tgz
CVE-2015-9251 jquery-1.8.1.min.js
CVE-2024-38999 requirejs-2.1.22.tgz
CVE-2019-11358 jquery-1.12.4.js
CVE-2022-23491 certifi-2021.5.30-py2.py3-none-any.whl
CVE-2020-28500 lodash-0.9.2.tgz
CVE-2023-28155 request-2.88.2.tgz
CVE-2022-3517 minimatch-3.0.4.tgz
CVE-2019-10744 lodash-2.4.2.tgz
CVE-2024-22195 Jinja2-3.0.1-py3-none-any.whl

Base branch total remaining vulnerabilities: 147
Base branch commit: null


Total libraries scanned: 108

Scan token: ad9c1e8c7cc74d0cac92235b031988ad