openvax / mhcflurry

Peptide-MHC I binding affinity prediction
http://openvax.github.io/mhcflurry/
Apache License 2.0
191 stars 57 forks source link

[Niah] Security upgrade tensorflow from (<2.3.0 >=2.2.0) to (2.4.1) #186

Closed niah-security closed 3 years ago

niah-security commented 3 years ago

Subject of the issue

Niah has created this Issue to report tensorflow vulnerable packages in the pip dependencies of this project.

https://pypi.org/project/tensorflow/

Vulnerability Scanning Report : Niah Report

Vulnerable for following couple of CVEs

CVE-2020-15266, CVE-2020-15265, CVE-2020-26266, CVE-2020-26268

Severity Couple of High, Medium Severity Vulnerabilities open in tensorflow dependencies.

Solution Use latest version of tensorflow "2.4.1" in requirements.txt file