Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk:Medium] setuptools Regular Expression Denial of Service (Due 08/12/2024 ) #6269

Open
1 task
pkfec opened this issue May 16, 2024 · 0 comments
Open
1 task
Labels
Security: moderate Remediate within 60 days Work: Back-end
Milestone

Comments

@pkfec
Copy link
Contributor

pkfec commented May 16, 2024

Regular Expression Denial of Service ReDoS in setuptools@65.5.0

Introduced through:

introduced by gevent@23.9.1 > zope.event@5.0 > setuptools@65.5.0

Remediation:

Pin setuptools@65.5.0 to setuptools@65.5.1

Completion criteria:

  • Pin setuptools to version setuptools@65.5.1 and verify snyk cli no longer flags setuptools as vulnerable package
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: moderate Remediate within 60 days Work: Back-end
Projects
Status: 🗄️ PI backlog
Development

No branches or pull requests

1 participant