Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

urllib3 version restrictions force use of vulnerable version #9339

Closed
tomwatson1024 opened this issue Jul 28, 2021 · 2 comments
Closed

urllib3 version restrictions force use of vulnerable version #9339

tomwatson1024 opened this issue Jul 28, 2021 · 2 comments

Comments

@tomwatson1024
Copy link

Conan 1.39.0 requires urllib3 >=1.25.8,<1.26. However versions of urllib3 before 1.26.5 are vulnerable to CVE-2021-33503.

Regardless of whether conan itself is affected by this issue the presence of urllib3 at this version is likely to cause problems in security scanning.

@memsharded memsharded added this to the 1.40 milestone Jul 28, 2021
@memsharded
Copy link
Member

Hi @tomwatson1024

Thanks for reporting this. We have been trying to upgrade this dependency, but unfortunately the ecosystem of many of our users is a bit delayed (very old distros, etc), so it had been a challenge to do it without breaking. As the URLs is Conan are quite controlled (Artifactory servers, recipes defined urls), doesn't seem a very problematic vuln.

But certainly, we should probably keep pushing for this, lets try to do it next 1.40.

@tapia
Copy link
Contributor

tapia commented Aug 20, 2021

Fixed on 1.40 (PR: #9405 )

@tapia tapia closed this as completed Aug 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants