Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MBT uses deprecated dependecy request 2.88.2, which has vulnerability CVE-2023-28155 #1059

Open
Bugaboo25 opened this issue Jul 10, 2023 · 2 comments

Comments

@Bugaboo25
Copy link

MBT 1.2.24 uses deprecated dependecy request 2.88.2 (through binwrap 0.2.3), which has vulnerability CVE-2023-28155 reported.
Binwrap itself has not been maintained for about 2 years.
We can not use MBT in our project as the Mend tool (which is part of our pipeline) is blocking the deployment.
Please provide workaround or fix.

@young-yang03
Copy link
Contributor

Hi @Bugaboo25
As we discussed in mail, this problem will be start to research on last sprint (11 Sep ~ 25 Sep) and binwrap will be replaced on Q4

@FrankVisuals
Copy link

Is there a recommended way to mitigate this? The issue is rated as critical by whitesource so end of september seems quite late for a fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants