CVE-2023-1712
Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack in version 1.15.0 and prior. A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1712, https://github.com/deepset-ai/haystack/pull/4535, https://github.com/deepset-ai/haystack/commit/5fc84904f198de661d5b933fde756aa922bf09f1, https://github.com/deepset-ai/haystack, https://huntr.dev/bounties/9a6b1fb4-ec9b-4cfa-af1e-9ce304924829, https://pypi.org/project/farm-haystack, https://github.com/advisories/GHSA-w7qg-j435-78qw