cvss4.7
how bad it is if exploited, out of 10
epss0.60%
chance of exploitation in the next 30 days
xyz scorenot scored
CyberXYZ composite, out of 10
fig. 01 — GHSA-mm79-jhqm-9j54, the advisory selected below
// advisories
GHSA-mm79-jhqm-9j54
MEDIUMCVE-2023-47125> ### CVSS: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C (4.4)
- Affected
- >=8.7.42, <8.7.55, >=9.5.29, <9.5.44, >=10.4.19, <10.4.41, >=11.3.2, <11.5.33, >=12.0.0, <12.4.8
- Fixed in
- 2.1.4
- Published
- 2023-11-14
- Source
- github
GHSANVDMITRE
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.
Checked 2026-09-22 at 00:51 UTC. The most recent advisory here was published 2023-11-14. Updated continuously from NVD, GHSA, OSV and CNA feeds.