Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SNYK finding: SNYK-PYTHON-CRYPTOGRAPHY-7161587 #4781

Closed
1 task
FuhuXia opened this issue Jun 6, 2024 · 3 comments
Closed
1 task

SNYK finding: SNYK-PYTHON-CRYPTOGRAPHY-7161587 #4781

FuhuXia opened this issue Jun 6, 2024 · 3 comments
Assignees
Labels
bug Software defect or bug compliance Relating to security compliance or documentation
Milestone

Comments

@FuhuXia
Copy link
Member

FuhuXia commented Jun 6, 2024

Date of report: 2024-05-29
Severity: HIGH
Due date: 2024-06-29

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

SNYK-PYTHON-CRYPTOGRAPHY-7161587 found in catalog.data.gov

@FuhuXia FuhuXia added compliance Relating to security compliance or documentation bug Software defect or bug labels Jun 6, 2024
@FuhuXia
Copy link
Member Author

FuhuXia commented Jun 6, 2024

snyk rates the Severity HIGH but OpenSSL Advisory mark it low, stating function SSL_free_buffers is rarely used.

@FuhuXia FuhuXia added this to the June 2024 milestone Jun 6, 2024
@hkdctol
Copy link
Contributor

hkdctol commented Jun 6, 2024

Clarify that it's actually low impact? Requires some research to confirm we don't have to address

@Jin-Sun-tts Jin-Sun-tts self-assigned this Jun 13, 2024
@Jin-Sun-tts
Copy link
Contributor

searched the source code but did not find any references to the function SSL_free_buffers.

Added a test-ssl option to the Makefile to check for potential future use of this function.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Software defect or bug compliance Relating to security compliance or documentation
Projects
Status: 🗄 Closed
Development

No branches or pull requests

3 participants