Skip to content

Remediate High urllib3 vulnerability #409

@Lilalamar

Description

@Lilalamar

Snyk reports the following High severity vulnerability in HumanCellAtlas/upload-service. Please remediate by the end of Q1 Milestone 1.

Description

urllib3

Suggested Remediation

Upgrade urllib3 to version 1.24.3 or higher.

Details

urllib3 is an HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to CRLF injection. Attacker who has the control of the requesting address parameter, could manipulate an HTTP header and attack an internal service.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions