1.1.1
6 years ago
18 days ago
Known vulnerabilities in the kedro package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
kedro is a Kedro helps you build production-ready data and analytics pipelines Affected versions of this package are vulnerable to Unsafe Dependency Resolution via the Note: This vulnerability bypasses the protections newly implemented through the How to fix Unsafe Dependency Resolution? Upgrade | [0.18.11,1.0.0) |
kedro is a Kedro helps you build production-ready data and analytics pipelines Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to improper validation in the Note: To exploit this vulnerability, an attacker would need write access to the session store files. How to fix Deserialization of Untrusted Data? Upgrade | [,0.19.9) |