PyPI: nextflow
CVE-2023-6481
Safety vulnerability ID: SFTY-20231204-32071
Safety legacy ID: pyup.io-73000
Nextflow has updated its Logback dependency from version 1.4.12 to 1.4.14 to address CVE-2023-6481. Note: The Nextflow launcher installer itself does not contain any vulnerable code. However, installing this package will result in using a version of the Nextflow core that may contain known vulnerabilities.
Overview
Nextflow has updated its Logback dependency from version 1.4.12 to 1.4.14 to address CVE-2023-6481. Note: The Nextflow launcher installer itself does not contain any vulnerable code. However, installing this package will result in using a version of the Nextflow core that may contain known vulnerabilities.
Advisory
Nextflow has updated its Logback dependency from version 1.4.12 to 1.4.14 to address CVE-2023-6481. Note: The Nextflow launcher installer itself does not contain any vulnerable code. However, installing this package will result in using a version of the Nextflow core that may contain known vulnerabilities.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more