Skip to content

CVE-2019-17495 for swagger-ui #28381

@hughlunnon

Description

@hughlunnon

Apache Airflow version

2.5.0

What happened

this issue #18383 still isn't closed. It seems like the underlying swagger-ui bundle has been abandoned by its maintainer, and we should instead point swagger UI bundle to this version which is kept up-to-date

https://github.com/bartsanchez/swagger_ui_bundle

edit : it seems like this might not be coming from the swagger_ui_bundle any more but instead perhaps from connexion. I'm not familiar with python dependencies, so forgive me if I'm mis-reporting this.

There are CVE scanner tools that notifies GHSA-c427-hjc3-wrfw using the apache/airflow:2.1.4

The python deps include swagger-ui-2.2.10 and swagger-ui-3.30.0 as part of the bundle. It is already included at ~/.local/lib/python3.6/site-packages/swagger_ui_bundle

swagger-ui-2.2.10 swagger-ui-3.30.0

What you think should happen instead

No response

How to reproduce

No response

Operating System

any

Versions of Apache Airflow Providers

No response

Deployment

Docker-Compose

Deployment details

No response

Anything else

No response

Are you willing to submit PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions