Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GHSL-2021-111 #50

Closed
kevinbackhouse opened this issue Aug 31, 2021 · 5 comments
Closed

GHSL-2021-111 #50

kevinbackhouse opened this issue Aug 31, 2021 · 5 comments
Assignees

Comments

@kevinbackhouse
Copy link

Hello,

The GitHub Security Lab team has found a potential vulnerability in your project. Please create a Security Advisory and invite me in to further disclose and discuss the vulnerability details and potential fix. Alternatively, please add a Security Policy containing a security email address to send the details to.

If you prefer to contact us by email, please reach out to [email protected] with reference to GHSL-2021-111.

Thank you,
Kevin Backhouse
GitHub Security Lab

@ptmcg
Copy link

ptmcg commented Aug 2, 2022

Is there any activity on this issue? dparse is used in flask-restx, which is currently failing ossaudit security check due to this project. (See python-restx/flask-restx#463.)

@yeisonvargasf yeisonvargasf self-assigned this Aug 2, 2022
@kevinbackhouse
Copy link
Author

This is a ReDoS issue, so it's low severity. It was fixed in the nexB fork but not here. I didn't publish our advisory because the issue hadn't been fully resolved, but it's been almost a year now so I'll publish it. It should appear here in the next few days.

@yeisonvargasf
Copy link
Member

@ptmcg this will be fixed in the next few days. Thanks @kevinbackhouse for the patience here, I'll address that before the advisory is published.

@yeisonvargasf
Copy link
Member

@kevinbackhouse I've created the draft security advisory, and I invited you.

@yeisonvargasf
Copy link
Member

I am closing this, thanks @kevinbackhouse!

bmwiedemann pushed a commit to bmwiedemann/openSUSE that referenced this issue Sep 29, 2022
https://build.opensuse.org/request/show/1006957
by user mcepl + RBrownFactory
- update to 0.6.1
  * Use non-deprecated ConfiParser method
- update to 0.6.0
  * Fork from upstream dparse that is unresponsive
  * Rename package to dparse2
  * Fix security issue for GHSL-2021-111pyupio/dparse#50
  * Drop support for Python < 3.6 and add support for up to 3.10
  * Drop support for updating requirements files
  * format code with black, sort imports
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants