Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulneratbility CVE-2022-40899 on future 0.18.2 #162

Closed
randori-ddejohn opened this issue Jan 11, 2023 · 2 comments
Closed

Security Vulneratbility CVE-2022-40899 on future 0.18.2 #162

randori-ddejohn opened this issue Jan 11, 2023 · 2 comments

Comments

@randori-ddejohn
Copy link

This package has a dependency on future, which has a recently disclosed vulnerability. The project is dead, so there likely won't be a fix. The only fix right now is to remove the dependency entirely.

https://www.mend.io/vulnerability-database/CVE-2022-40899
https://nvd.nist.gov/vuln/detail/CVE-2022-40899
PythonCharmers/python-future#612
PythonCharmers/python-future#610

I attempted to do this myself but was denied access trying to push a branch to remote.

@richardpenman
Copy link
Owner

Yeah random people can't push to master, but you could open a pull request for review. I would be open to removing Python2 support so this future dependency is no longer required.

@richardpenman
Copy link
Owner

Have removed futures dependency in latest commit

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants