doccano@1.0.0 vulnerabilities

doccano, text annotation tool for machine learning practitioners

Direct Vulnerabilities

Known vulnerabilities in the doccano package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Server-side Request Forgery (SSRF)

doccano is a text annotation tool for machine learning practitioners.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the model_attribs parameter on the request-testing endpoint. An admin user who can send a request that gets a valid JSON response can escalate privileges.

How to fix Server-side Request Forgery (SSRF)?

There is no fixed version for doccano.

[0,)
  • M
Clickjacking

doccano is a text annotation tool for machine learning practitioners.

Affected versions of this package are vulnerable to Clickjacking via the X-Frame-Options header which is disabled.

How to fix Clickjacking?

Upgrade doccano to version 1.0.1 or higher.

[0,1.0.1)