Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Safety vulnerability 52495 for package 'setuptools' #120

Closed
RobPasMue opened this issue Aug 28, 2023 · 0 comments · Fixed by #121
Closed

Safety vulnerability 52495 for package 'setuptools' #120

RobPasMue opened this issue Aug 28, 2023 · 0 comments · Fixed by #121

Comments

@RobPasMue
Copy link
Member

RobPasMue commented Aug 28, 2023

A new security advisory was open in this repository. See https://github.com/ansys/pyansys-tools-report/security/advisories/GHSA-2q8c-5fcp-rq86.


NOTE

Please update the security advisory status after evaluating. Publish the advisory
once it has been verified (since it has been created in draft mode).


Description

Setuptools 65.5.1 includes a fix for CVE-2022-40897: Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages

More information

Visit https://pyup.io/v/52495/f17 to find out more information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant