-
Notifications
You must be signed in to change notification settings - Fork 88
[VUL-14360][VUL-9146][VUL-11518][VUL-11519] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 #1555
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE
The Needs Review labels were added based on the following file changes. Team @datarobot/buzok (#buzok) was assigned because of changes in files:public_dropin_environments/python311_genai_agents/requirements.txt Team @datarobot/core-modeling (#predictive-ai) was assigned because of changes in files:public_dropin_environments/python3_keras/env_info.json public_dropin_environments/python3_keras/requirements.txt public_dropin_environments/python3_pmml/env_info.json public_dropin_environments/python3_pmml/requirements.txt public_dropin_environments/python3_pytorch/env_info.json public_dropin_environments/python3_pytorch/requirements.txt public_dropin_environments/python3_sklearn/env_info.json public_dropin_environments/python3_sklearn/requirements.txt public_dropin_environments/python3_xgboost/env_info.json public_dropin_environments/python3_xgboost/requirements.txt public_dropin_environments/r_lang/env_info.json public_dropin_environments/r_lang/requirements.txt Team @datarobot/genai-systems (#genai-systems) was assigned because of changes in files:public_dropin_environments/java_codegen/env_info.json public_dropin_environments/java_codegen/requirements.txt public_dropin_environments/python311/env_info.json public_dropin_environments/python311/requirements.txt public_dropin_environments/python3_keras/env_info.json public_dropin_environments/python3_keras/requirements.txt public_dropin_environments/python3_onnx/env_info.json public_dropin_environments/python3_onnx/requirements.txt public_dropin_environments/python3_pmml/env_info.json public_dropin_environments/python3_pmml/requirements.txt public_dropin_environments/python3_pytorch/env_info.json public_dropin_environments/python3_pytorch/requirements.txt public_dropin_environments/python3_sklearn/env_info.json public_dropin_environments/python3_sklearn/requirements.txt public_dropin_environments/python3_xgboost/env_info.json public_dropin_environments/python3_xgboost/requirements.txt public_dropin_environments/r_lang/env_info.json public_dropin_environments/r_lang/requirements.txt If you think that there are some issues with ownership, please discuss with C&A domain at #sdtk slack channel and create PR to update DRCODEOWNERS\CODEOWNERS file. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Label Needs Review: Core Modeling was removed because @eric-s-s is part of Predictive AI domain. |
jarvis please cherry-pick this release/11.1 |
…E-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555) * [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE * Reconcile dependencies, updated IDs, tags * [RAPTOR-13877] Bumped up a version of urllib3 for CVE * [RAPTOR-13875] Bumped up a version of urllib3 for CVE * [RAPTOR-13873] Bumped up a version of urllib3 for CVE * [RAPTOR-13871] Bumped up a version of urllib3 for CVE * [RAPTOR-13868] Bumped up a version of urllib3 for CVE * [RAPTOR-13866] Bumped up a version of urllib3 for CVE * [RAPTOR-13864] Bumped up a version of urllib3 for CVE * [RAPTOR-13862] Bumped up a version of urllib3 for CVE * [RAPTOR-13879] Bumped up a version of urllib3 for CVE * [BUZZOK-26501] Bumped up a version of urllib3 for CVE * [RAPTOR-12952] Bumped up a version of requests for CVE * [RAPTOR-12949] Bumped up a version of requests for CVE * [RAPTOR-12947] Bumped up a version of requests for CVE * [RAPTOR-12945] Bumped up a version of requests for CVE * [RAPTOR-12942] Bumped up a version of requests for CVE * [RAPTOR-12940] Bumped up a version of requests for CVE * [RAPTOR-12938] Bumped up a version of requests for CVE * [RAPTOR-12936] Bumped up a version of requests for CVE * [RAPTOR-12933] Bumped up a version of requests for CVE * Reconcile dependencies, updated IDs, tags --------- Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
…E-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555) * [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE * Reconcile dependencies, updated IDs, tags * [RAPTOR-13877] Bumped up a version of urllib3 for CVE * [RAPTOR-13875] Bumped up a version of urllib3 for CVE * [RAPTOR-13873] Bumped up a version of urllib3 for CVE * [RAPTOR-13871] Bumped up a version of urllib3 for CVE * [RAPTOR-13868] Bumped up a version of urllib3 for CVE * [RAPTOR-13866] Bumped up a version of urllib3 for CVE * [RAPTOR-13864] Bumped up a version of urllib3 for CVE * [RAPTOR-13862] Bumped up a version of urllib3 for CVE * [RAPTOR-13879] Bumped up a version of urllib3 for CVE * [BUZZOK-26501] Bumped up a version of urllib3 for CVE * [RAPTOR-12952] Bumped up a version of requests for CVE * [RAPTOR-12949] Bumped up a version of requests for CVE * [RAPTOR-12947] Bumped up a version of requests for CVE * [RAPTOR-12945] Bumped up a version of requests for CVE * [RAPTOR-12942] Bumped up a version of requests for CVE * [RAPTOR-12940] Bumped up a version of requests for CVE * [RAPTOR-12938] Bumped up a version of requests for CVE * [RAPTOR-12936] Bumped up a version of requests for CVE * [RAPTOR-12933] Bumped up a version of requests for CVE * Reconcile dependencies, updated IDs, tags --------- Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
…19] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555) (#1556) * [VUL-14360][VUL-9146][VUL-11518][VUL-11519] Fixing CVE-2025-48379, CVE-2024-47081, CVE-2025-50181 and CVE-2025-50182 (#1555) * [RAPTOR-14094][RAPTOR-14095][RAPTOR-14096][RAPTOR-14097][RAPTOR-14098][RAPTOR-14099][RAPTOR-14100][RAPTOR-14101][RAPTOR-14102] Bumped up a version of Pillow for CVE * Reconcile dependencies, updated IDs, tags * [RAPTOR-13877] Bumped up a version of urllib3 for CVE * [RAPTOR-13875] Bumped up a version of urllib3 for CVE * [RAPTOR-13873] Bumped up a version of urllib3 for CVE * [RAPTOR-13871] Bumped up a version of urllib3 for CVE * [RAPTOR-13868] Bumped up a version of urllib3 for CVE * [RAPTOR-13866] Bumped up a version of urllib3 for CVE * [RAPTOR-13864] Bumped up a version of urllib3 for CVE * [RAPTOR-13862] Bumped up a version of urllib3 for CVE * [RAPTOR-13879] Bumped up a version of urllib3 for CVE * [BUZZOK-26501] Bumped up a version of urllib3 for CVE * [RAPTOR-12952] Bumped up a version of requests for CVE * [RAPTOR-12949] Bumped up a version of requests for CVE * [RAPTOR-12947] Bumped up a version of requests for CVE * [RAPTOR-12945] Bumped up a version of requests for CVE * [RAPTOR-12942] Bumped up a version of requests for CVE * [RAPTOR-12940] Bumped up a version of requests for CVE * [RAPTOR-12938] Bumped up a version of requests for CVE * [RAPTOR-12936] Bumped up a version of requests for CVE * [RAPTOR-12933] Bumped up a version of requests for CVE * Reconcile dependencies, updated IDs, tags --------- Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com> * Reconcile dependencies, updated IDs, tags --------- Co-authored-by: svc-harness-git2 <svc-harness-git2@datarobot.com>
This repository is public. Do not put here any private DataRobot or customer's data: code, datasets, model artifacts, .etc.
Summary
Pillow dependency for DRUM is unpinned but we have the pin in execution environments.
For CVE-2025-48379 we have to use Pillow version 11.3.0
Also I bumped version of
requests
to solve CVE-2024-47081 and urllib3 for CVE-2025-50181 and CVE-2025-50182 .Rationale
All that CVEs are affecting release 11.1