Python Vulnerabilities #555
MikeNikolayev
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I installed latest tag (built 6 month ago) and found vulnerabilities list.
All of them are already fixed in requirements file. Do you mind building a new tag with fixes?
The list
Library:
idna (METADATA)CVE-2024-3651MEDIUMfixed3.63.7python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()Library:
requests (METADATA)CVE-2024-35195MEDIUM2.31.02.32.0requests: subsequent requests to the same host ignore cert verificationLibrary:
sqlparse (METADATA)CVE-2024-4340HIGH0.4.40.5.0sqlparse: parsing heavily nested list leads to denial of serviceLibrary:
urllib3 (METADATA)CVE-2024-37891MEDIUM1.26.181.26.19, 2.2.2urllib3: proxy-authorization request header is not stripped during cross-origin redirectsBeta Was this translation helpful? Give feedback.
All reactions