kubeflow-pipelines-visualization-server
2.4.0-r0
7.8
CVSS V3
Status
Fixed version
2.4.0-r0Status
Impact
The vulnerability is in the jinja2 package which is not a direct dependency. Attempting to upgrade jinja2 one major version to 3.1.5 to remediate the CVE results in multiple other packages needing updates: bokeh, Markupsafe, nbconvert ...- all requiring major version bumps. The result is multiple failures in itegration test due to failed python imports. As such - bumping major versions like this is a risk to functionality so I am marking this as pending-upstream-fix
Status