b2
The command-line tool that gives easy access to all of the capabilities of B2 Cloud Storage
Activity
- Latest release
- 12h ago
- Total releases
- 88
- Cadence
- ~32 days
- Last 12 months
- 7
Reach
- Stars
- 631
Details
- License
- MIT
- First release
- Feb 17, 2016
| Version | Released | |
|---|---|---|
5.0.0
major
| ||
4.8.0
minor
| ||
4.7.1
patch
| ||
4.7.0
minor
| ||
4.6.0
minor
| ||
4.5.1
patch
| ||
4.5.0
minor
| ||
4.4.2
patch
| ||
4.4.1
patch
| ||
4.4.0
minor
| ||
4.3.3
patch
| ||
4.3.2
patch
| ||
4.3.1
patch
| ||
4.3.0
minor
| ||
4.2.0
minor
| ||
4.1.0
minor
| ||
4.0.3
patch
| ||
4.0.2
patch
| ||
4.0.1
patch
| ||
4.0.0
major
| ||
3.19.1
patch
| ||
3.19.0
minor
| ||
3.18.0
minor
| ||
3.17.0
minor
| ||
3.16.1
patch
| ||
3.16.0
minor
| ||
3.15.0
minor
| ||
3.14.0
minor
| ||
3.13.1
patch
| ||
3.13.0
minor
| ||
3.12.0
minor
| ||
3.11.0
minor
| ||
3.10.1
patch
| ||
3.10.0
minor
| ||
0.0.0
initial
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev | ||
3.9.0
minor
| ||
3.8.0
minor
| ||
3.7.1
patch
| ||
3.7.0
minor
| ||
3.7.0a1
pre
| ||
3.6.0
minor
| ||
3.5.0
minor
| ||
3.4.0
minor
| ||
3.3.0
minor
| ||
3.2.1
patch
| ||
3.2.0
minor
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev | ||
3.0.3
patch
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev | ||
3.0.2
patch
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2022-23653
GHSA-8wr4-2wm6-w3pr
PYSEC-2022-32
Feb 24, 2022
B2 Command Line Tool TOCTOU application key disclosure
Medium
Local
High
Low
None
ImpactLinux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file ( RemediationUsers that have not yet run Users that have run Users that have run WorkaroundsIf B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.0
0.3.14
0.4.0
0.4.10
0.4.2
0.4.4
0.4.6
0.4.8
0.5.0
0.5.2
0.5.4
0.5.6
+ 32 more Show less
0.6.0
0.6.2
0.6.4
0.6.6
0.6.8
0.7.0
0.7.2
0.7.4
1.0.0
1.1.0
1.2.0
1.3.0
1.3.2
1.3.4
1.3.6
1.3.8
1.4.0
1.4.2
2.0.0
2.0.2
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
Fixed in
3.2.1
References
Updated Sep 04, 2024 · Source: OSV.dev |