DHI / DHI/mikecore-python

Known vulnerabilities in shared libraries xerces-c which mikecore depends on.Can you help upgrade to patch versions?

Open
#21 3 comments 1 reaction 0 assignees View on GitHub
Dominant language
Python
Stars
5
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Hi, @jsmariegaard , @ecomodeller , I'd like to report a vulnerability issue in **mikecore_0.2.0**.
### Dependency Graph between Python and Shared Libraries
![image](https://user-images.githubusercontent.com/102780639/161250908-f4f55673-dcaf-408c-bef2-09f674f80813.png)
### Issue Description
As shown in the above dependency graph, **mikecore_0.2.0** directly or transitively depends on ***3*** C libraries (.so). However, I noticed that one C library is vulnerable, containing the following CVEs:
`libxerces-c-3.1.so` from C project **xerces-c(version:3.1.1)** exposed ***2*** vulnerabilities:
[CVE-2018-1311](https://nvd.nist.gov/vuln/detail/CVE-2018-1311), [CVE-2015-0252](https://nvd.nist.gov/vuln/detail/CVE-2015-0252)
### Suggested Vulnerability Patch Versions
***xerces-c*** has fixed the vulnerabilities in versions ***>=3.2.3***

Python build tools cannot report vulnerable C libraries, which may induce potential security issues to many downstream Python projects.
As a popular python package (**mikecore** has **2,265** downloads per month), could you please upgrade the above shared libraries to their patch versions?

Thanks for your help~
Best regards,
Andy

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.