You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi @tuck1s, we reviewed the urllib3 issue when it was disclosed. Requests doesn’t use urllib3’s redirect functionality and we’ve already patched a sinusale vulnerability in #4718.
Good to know, thanks. This came to my attention because Github are sending out warning notices by email, like this, for transitive dependencies. I assume it's likely other folks will also get this warning.
Known high severity security vulnerability detected in urllib3 < 1.23 defined in Pipfile.lock.
Pipfile.lock update suggested: urllib3 ~> 1.23.
Summary.
CVE-2018-20060 identifies a vulnerability in
urllib3
before version 1.23.This project
Pipfile
-->Pipfile.lock
is using version 1.22 currently: hereThe text was updated successfully, but these errors were encountered: