Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2018-20060 #4907

Closed
tuck1s opened this issue Dec 12, 2018 · 2 comments
Closed

Address CVE-2018-20060 #4907

tuck1s opened this issue Dec 12, 2018 · 2 comments

Comments

@tuck1s
Copy link

tuck1s commented Dec 12, 2018

Summary.

CVE-2018-20060 identifies a vulnerability in urllib3 before version 1.23.

This project Pipfile --> Pipfile.lock is using version 1.22 currently: here

@nateprewitt
Copy link
Member

Hi @tuck1s, we reviewed the urllib3 issue when it was disclosed. Requests doesn’t use urllib3’s redirect functionality and we’ve already patched a sinusale vulnerability in #4718.

@tuck1s
Copy link
Author

tuck1s commented Dec 12, 2018

Good to know, thanks. This came to my attention because Github are sending out warning notices by email, like this, for transitive dependencies. I assume it's likely other folks will also get this warning.

Known high severity security vulnerability detected in urllib3 < 1.23 defined in Pipfile.lock.
Pipfile.lock update suggested: urllib3 ~> 1.23.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Sep 6, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants