galaxy-data@20.9.1 vulnerabilities

Galaxy datatype framework and datatypes

Direct Vulnerabilities

Known vulnerabilities in the galaxy-data package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary File Read

galaxy-data is a Galaxy datatype framework and datatypes

Affected versions of this package are vulnerable to Arbitrary File Read due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running.

How to fix Arbitrary File Read?

Upgrade galaxy-data to version 23.0.1 or higher.

[,23.0.1)