Race Condition Affecting that-depends package, versions [,1.16.2)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-THATDEPENDS-7885078
- published 3 Sep 2024
- disclosed 1 Sep 2024
- credit Unknown
How to fix?
Upgrade that-depends
to version 1.16.2 or higher.
Overview
that-depends is a Simple Dependency Injection framework
Affected versions of this package are vulnerable to Race Condition. An attacker could cause inconsistent states or denial of service by exploiting this vulnerability and creating multiple instances.