Junglewise Threat Intelligence

CVE-2023-31143: PYSEC-2023-64 - mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior

CVE-2023-31143 · Severity: low · CVSS 3.1 · Published 2023-05-09

Technologies: mage-ai (PyPI). Vendors: PyPI.

Executive brief

mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by users who are not signed in or do not have editor permissions. Version 0.8.72 contains a fix for this issue.

Affected products

  • PyPI mage-ai

Related threats