Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pyyaml version to >=4.2b1 for CVE-2017-18342 #29

Closed
wants to merge 2 commits into from

Conversation

bitdivision
Copy link
Contributor

What? and Why?

Github is warning about a CVE on all repos which depend on sdc-cryptography. This updates pyyaml to avoid the issue.

Checklist

  • CHANGELOG.md updated? (if required)

@bitdivision
Copy link
Contributor Author

4.2b1 is a prerelease and PyYAML have not released a new version to fix this CVE. This is an old security issue and is noted in the documentation.

Development on 4.2 seems to have stalled in July 2017, there hasn't been another release since then. The original fix was reverted. Some discussion of the github reporting here: yaml/pyyaml#243 and the underlying issue / release plan here: yaml/pyyaml#193

We do not use the load method in this project, so the original CVE does not apply.

I would suggest that the reporting is removed by github, since there is no released version to fix it.

Closing for now, feel free to reopen if you disagree.

@pricem14pc pricem14pc deleted the fix-cve-pyyaml branch July 6, 2023 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant