ActivePython Enterprise Versions with Fix: 2.7.18.9
This is both a feature change release and a content release. At this release, the new back end regains support for projects that contain OS X 11 builds. Tkinter/Tcl support has been restored for Windows.
Known issues
(Specific to 2.7.18.9) Scipy support removed from all platforms for this release.
(Not version specific) ActivePython ships with dormant pip/setuptools by default. These can be replaced post-installation using python -m ensurepip, but if a specific pip or setuptools version is desired that should be added to the configuration.
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.8 and prior
Severity: High
URL: CVE-2022-45061
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.8 and prior
Severity: High
URL: CVE-2022-48560
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.8 and prior
Severity: Medium
URL: CVE-2017-18207
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.8 and prior
Severity: Medium
URL: CVE-2022-48566
No changes
No changes
ActivePython Enterprise Versions with Fix: 2.7.18.8
This is both a feature change release needed to migrate the Python2 builders to a new back end, and a content release. At this release, the new back end supports projects that contain Linux builds for Glibc 2.17 and/or 2.28, and adds support for Windows 64 bit. Other platforms remain at the 2.7.18.6 release.
Known issues
Windows builds have Tkinter/Tcl support removed for this release.
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.7 and prior
Severity: Critical
URL: CVE-2022-48565
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.7 and prior
Severity: High
URL: CVE-2023-24329
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.7 and prior
Severity: Medium
URL: CVE-2023-40217
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Critical
URL: CVE-2022-22817
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Critical
URL: CVE-2022-24303
Package: gevent
Versions Impacted: 1.3.2.post0
Severity: Critical
URL: CVE-2023-41419
Package: cryptography
Versions Impacted: 3.3.2
Severity: High
URL: CVE-2023-49083
Package: mako
Versions Impacted: 1.1.6
Severity: High
URL: CVE-2022-40023
Package: pillow
Versions Impacted: 6.2.2.5
Severity: High
URL: 2020-10379
Package: twisted
Versions Impacted: 20.3.0.1
Severity: High
URL: CVE-2022-21712
Package: twisted
Versions Impacted: 20.3.0.1
Severity: High
URL: CVE-2022-24801
Package: cryptography
Versions Impacted: 3.3.2
Severity: Medium
URL: CVE-2023-23931
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2020-10177
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2020-10378
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2020-10994
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2020-35655
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2021-25292
Package: pillow
Versions Impacted: 6.2.2.5
Severity: Medium
URL: CVE-2021-28678
Package: pygments
Versions Impacted: 2.5.2.1
Severity: Medium
URL: CVE-2022-40896
Package: tornado
Versions Impacted: 5.1.1
Severity: Medium
URL: CVE-2023-28370
Package: twisted
Versions Impacted: 20.3.0.1
Severity: Medium
URL: CVE-2022-39348
Package: zlib
Versions Impacted: 1.2.12.1
Severity: Critical
URL: CVE-2023-45853
Package: expat
Versions Impacted: 2.5.0
Severity: High
URL: CVE-2023-52425
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2020-7595
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2021-3517
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2021-3518
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2019-20388
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2022-23308
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2022-40303
Package: libxml2
Versions Impacted: 2.9.10
Severity: High
URL: CVE-2022-40304
Package: libxslt
Versions Impacted: 1.1.34
Severity: High
URL: CVE-2021-30560
Package: expat
Versions Impacted: 2.5.0
Severity: Medium
URL: CVE-2023-52426
Package: libxml2
Versions Impacted: 2.11.5
Severity: Medium
URL: CVE-2023-45322
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2016-3709
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2021-3537
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2021-3541
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2020-24977
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2022-29824
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2023-28484
Package: libxml2
Versions Impacted: 2.9.10
Severity: Medium
URL: CVE-2023-29469
Package: libxslt
Versions Impacted: 1.1.34
Severity: Medium
URL: CVE-2022-29824
ActivePython Enterprise Versions with Fix: 2.7.18.7
This is a feature change release needed to migrate the Python2 builders to a new back end. At this release, the new back end supports projects that contain only Linux builds for Glibc 2.17 and/or 2.28. Projects that include other platforms will remain on the previous release.
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.6 and prior
Severity: High
URL: CVE-2022-0391
No Changes
ActivePython Enterprise Versions with Fix: 2.7.18.6
No Changes
No Changes
ActivePython Enterprise Versions with Fix: 2.7.18.6
No Changes
Package: urllib3
Versions Impacted: 1.26.15
Severity: High
URL: CVE-2023-43804
Package: OpenSSL
Versions Impacted: 1.1.1.22
Severity: High
URL: CVE-2023-4807
Package: wheel
Versions Impacted: 0.33.4
Severity: High
URL: CVE-2022-40898
Package: urllib3
Versions Impacted: 1.26.15
Severity: Medium
URL: CVE-2023-45803
Package: requests
Versions Impacted: 2.26.0
Severity: ?
URL: unreported
ActivePython Enterprise Versions with Fix: 2.7.18.6
No Changes
Package: certifi
Versions Impacted: 2021.10.8
Severity: Critical
URL: CVE-2023-37920
Package: certifi
Versions Impacted: 2021.10.8
Severity: High
URL: CVE-2022-23491
Package: lxml
Versions Impacted: 4.6.3
Severity: High
URL: CVE-2022-2309
Package: lxml
Versions Impacted: 4.6.3
Severity: High
URL: CVE-2021-43818
Package: pygments
Versions Impacted: 2.5.2
Severity: High
URL: CVE-2021-20270
Package: pyjwt
Versions Impacted: 1.7.1
Severity: High
URL: CVE-2022-29217
Package: OpenSSL
Versions Impacted: 1.11.0.21
Severity: Medium
URL: CVE-2023-3817
ActivePython Enterprise Versions with Fix: 2.7.18.6
No Changes
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2020-10379
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2020-35653
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27923
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27922
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27921
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25290
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25291
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25293
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-28676
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-28677
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-23437
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2022-45198
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2022-45199
Package: OpenSSL
Versions Impacted: 1.1.1t and older
Severity: High
URL: CVE-2023-0464
Package: OpenSSL
Versions Impacted: 1.1.1t and older
Severity: High
URL: CVE-2023-2650
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2020-10994
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2020-10378
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2020-10177
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2020-35655
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2021-25292
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2021-28678
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2021-28675
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2022-22816
Package: pillow
Versions Impacted: 6.2.2.3
Severity: Medium
URL: CVE-2022-22815
Package: OpenSSL
Versions Impacted: 1.1.1t and older
Severity: Medium
URL: CVE-2023-0466
Package: OpenSSL
Versions Impacted: 1.1.1t and older
Severity: Medium
URL: CVE-2023-0465
ActivePython Enterprise Versions with Fix: 2.7.18.6
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.5 and prior
Severity: High
URL: CVE-2015-5652
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.5 and prior
Severity: High
URL: CVE-2017-17522
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.5 and prior
Severity: High
URL: CVE-2020-10735
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Critical
URL: CVE-2021-25287
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Critical
URL: CVE-2021-25288
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Critical
URL: CVE-2021-34552
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Critical
URL: CVE-2022-22817
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Critical
URL: CVE-2022-24303
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2020-35653
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27923
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27922
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-27921
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25290
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25291
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-25293
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-28676
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-28677
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2021-23437
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2022-45198
Package: pillow
Versions Impacted: 6.2.2.1
Severity: High
URL: CVE-2022-45199
Package: OpenSSL
Versions Impacted: 1.1.1s and older
Severity: High
URL: CVE-2022-4450
Package: OpenSSL
Versions Impacted: 1.1.1s and older
Severity: High
URL: CVE-2023-0286
Package: OpenSSL
Versions Impacted: 1.1.1s and older
Severity: High
URL: CVE-2023-0215
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2020-35655
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2021-25292
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2021-28678
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2021-28675
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2022-22816
Package: pillow
Versions Impacted: 6.2.2.1
Severity: Medium
URL: CVE-2022-22815
Package: OpenSSL
Versions Impacted: 1.1.1s and older
Severity: Medium
URL: CVE-2022-4304
ActivePython Enterprise Versions with Fix: 2.7.18.5
No Changes
Package: expat
Versions Impacted: 2.4.7
Severity: Critical
URL: CVE-2022-40674
Package: zlib
Versions Impacted: 1.2.12
Severity: Critical
URL: CVE-2022-37434
Package: expat
Versions Impacted: 2.4.7
Severity: High
URL: CVE-2022-43680
OpenSSL upgraded to 1.1.1s
ActivePython Enterprise Versions with Fix: 2.7.18.5
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.1, .2, .3, .4
Severity: High
URL: CVE-2022-0391
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-22822
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-22823
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-22824
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-23852
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-23990
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-25235
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-25236
Package: expat
Versions Impacted: 2.2.9
Severity: Critical
URL: CVE-2022-25315
Package: OpenSSL 1.11.0.15
Versions Impacted: 1.1.1.o
Severity: Critical
URL: CVE-2022-2068
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2021-45960
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2021-46143
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2022-22825
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2022-22826
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2022-22827
Package: expat
Versions Impacted: 2.2.9
Severity: High
URL: CVE-2022-25314
Package: OpenSSL
Versions Impacted: 1.1.1.o
Severity: High
URL: CVE-2022-2097
Package: expat
Versions Impacted: 2.2.9
Severity: Medium
URL: CVE-2022-25313
Package: expat
Versions Impacted: 2.2.9
Severity: Unscored
URL: CVE-2013-0340
ActivePython Enterprise Versions with Fix: 2.7.18.4
No changes
Package: OpenSSL
Versions Impacted: 1.1.1.m
Severity: Critical
URL: CVE-2022-1292
Package: OpenSSL
Versions Impacted: 1.1.1.m
Severity: High
URL: CVE-2022-0778
ActivePython Enterprise Versions with Fix: 2.7.18.4
No changes
Package: OpenSSL
Versions Impacted: 1.1.1.l
Severity: Med
URL: CVE-2021-4160
ActivePython Enterprise Versions with Fix: 2.7.18.4
No changes
Package: OpenSSL
Versions Impacted: 1.1.1.k
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3711
Package: Pillow
Versions Impacted: 6.2.2
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-25289
Package: OpenSSL
Versions Impacted: 1.1.1k
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3712
Package: Pillow
Versions Impacted: 6.2.2
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-11538
Package: Pillow
Versions Impacted: 6.2.2
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-35654
Package: requests
Versions Impacted: 2.1.0
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-18074 \
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22134
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22135
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22137
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22144
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22145
Package: ElasticSearch
Versions Impacted: 7.11.0
Severity: Medium (6)
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22147
ActivePython Enterprise Versions with Fix: 2.7.18.4
No changes
Package: eventlet
Versions Impacted: Versions before 0.31.0
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21419
Package: lxml
Versions Impacted: Versions before 4.6.3
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-28957 \
Legend - Number present at each severity (C)ritical, (H)igh, (M)edium
\
ActivePython Enterprise Versions with Fix: 2.7.18.4
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.1, .2, & .3
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23336
Package: OpenSSL
Versions Impacted: Versions before 1.2
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23840
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2018-0732
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23840
Package: OpenSSL
Versions Impacted: Versions before 1.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-1971
Package: OpenSSL
Versions Impacted: Versions before 1.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23841
Package: OpenSSL
Versions Impacted: Versions before 1.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3449
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1547
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1551
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-1971
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23841
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Low
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1552
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Low
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-1563
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Low
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-1968
Package: OpenSSL
Versions Impacted: Versions before 1.2.21.2
Severity: Low
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-23839
ActivePython Enterprise Versions with Fix: 2.7.18.3
Language Core: Python Core (Cpython)
Versions Impacted: Python versions 2.7.18.2 & 3
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3177
NOTE: Please see separate CVE notification attached.
Package: bzip2
Versions Impacted: Versions before 1.0.7
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-12900 \
Package: cryptography
Versions Impacted: In the cryptography package before 3.3.2
Severity: Critical
URL:https://nvd.nist.gov/vuln/detail/CVE-2020-36242
Package: pyYAML
Versions Impacted: PyYAML library in versions before 5.4
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-14343
Package: elasticsearch
Versions Impacted: Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2
Severity: High
URL:https://nvd.nist.gov/vuln/detail/CVE-2020-7009
Package: httplib2
Versions Impacted: In httplib2 before version 0.19.0
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-21240
Package: lxml
Versions Impacted: Versions from 1.2 up to 4.6.2
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-27783 \
Package: httplib2
Versions Impacted: In httplib2 before version 0.18.0
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-11078
Package: jinja2
Versions Impacted: package jinja2 from 0.0.0 and before 2.11.3
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-28493
Package: bleach
Versions Impacted: Bleach versions before 3.1.4.
Severity: Medium
CVE details: CVE-2020-6817
Package: openssl
Versions Impacted: All OpenSSL 1.1.1 and 1.0.2 versions
Severity: Medium
CVE details: CVE-2020-1971
ActivePython Enterprise Versions with Fix: 2.7.18.2
Language Core: Python core (CPython)
Versions Impacted: 2.7.18.1
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-27619
Package: Python core (CPython)
Versions Impacted: 2.7.18.1
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-26116 \
Package: Python core (CPython)
Versions Impacted: 2.7.18.1
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-20907
Package: libxslt
Versions Impacted: Versions before 1.1.34
ActivePython Enterprise Versions with Fix:1.1.34
Severity: Critical
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11068
Package: urllib3
Versions Impacted: Versions before 1.25.8
ActivePython Enterprise Versions with Fix: 1.25.8 or higher
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-7212
\
Package: pySAML
Versions Impacted: Versions before 5.0.0
ActivePython Enterprise Versions with Fix: 5.0.0
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-5390
Package: urllib3
Versions Impacted: Versions before 1.25.9
ActivePython Enterprise Versions with Fix: 1.25.9 or higher
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-26137
\
Package: Twisted
Versions Impacted: Versions before 19.2.1
ActivePython Enterprise Versions with Fix: 19.2.1 or higher
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-12387
ActivePython Enterprise Versions with Fix: 2.7.18.1
Language Core: Python core (CPython)
Versions Impacted: 2.7.18
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-8492 \
Package: Pillow
Versions Impacted: In Pillow before 6.2.2
ActivePython Enterprise Versions with Fix: 6.2.2 or higher
Severity: Critical
URL:
https://nvd.nist.gov/vuln/detail/CVE-2020-5311
https://nvd.nist.gov/vuln/detail/CVE-2020-5310
https://nvd.nist.gov/vuln/detail/CVE-2020-5312
https://nvd.nist.gov/vuln/detail/CVE-2020-5313
Package: Python core dependency (SQLite )
Versions Impacted: All versions prior to 3.31.1
Severity: High
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-11655
Package: Bleach
Versions Impacted: In Mozilla Bleach before 3.1.2
ActivePython Enterprise Versions with Fix: 3.1.2 or higher
Severity: Medium
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-6816
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-6802
If you have any questions, please contact enterprise-support@activestate.com.