Skip to content

BUG: vulnerabilities found in the latest pandas v2.2.3 #60657

@OlgasAcc

Description

@OlgasAcc

Pandas version checks

  • I have checked that this issue has not already been reported.

  • I have confirmed this bug exists on the latest version of pandas.

  • I have confirmed this bug exists on the main branch of pandas.

Reproducible Example

Scan the latest version using Sonatype/Aqua security scanners.
Expected 2 vulns to be reported: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9880,
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13091

Issue Description

There are 2 critical security vulnerabilities found in v2.2.3:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9880,
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13091.

We didn't get response on email sent to [email protected].
These 2 issues block upcoming release of our project, could your team take a look and fix them asap?

Thanks

Expected Behavior

Should pass Sonatype and Aqua security scanners with no issues found.

Installed Versions

Replace this line with the output of pd.show_versions()

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugNeeds InfoClarification about behavior needed to assess issue

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions