From 9b3eb6fa25affaff695f5f5b2fe8b51877516622 Mon Sep 17 00:00:00 2001 From: Lefteris Karapetsas Date: Sat, 5 Jan 2019 09:57:55 +0100 Subject: [PATCH] Upgrade scenarioplayer's pyyaml dependency Pyyaml had an arbitrary code execution vulnerability in previous versions. Check https://nvd.nist.gov/vuln/detail/CVE-2017-18342 --- tools/scenario-player/requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/scenario-player/requirements.txt b/tools/scenario-player/requirements.txt index f3ba82d911..cc85b42909 100644 --- a/tools/scenario-player/requirements.txt +++ b/tools/scenario-player/requirements.txt @@ -1,3 +1,3 @@ urwid>=2.0.1 raiden>=0.10.0 -pyyaml==3.13 +pyyaml==4.2b4