Skip to content

Conversation

@tao12345666333
Copy link
Member

PyYAML 5.3.1 has a public vulnerability CVE-2020-143431 and
CVSS score is 9.82.

We need to update it to version 5.4+.

Signed-off-by: Jintao Zhang zhangjintao9020@gmail.com

What this PR does / why we need it:

Pre-submission checklist:

  • Did you explain what problem does this PR solve? Or what new features have been added?
  • Have you added corresponding test cases?
  • Have you modified the corresponding document?
  • Is this PR backward compatible? If it is not backward compatible, please discuss on the mailing list first

PyYAML 5.3.1 has a public vulnerability CVE-2020-14343[1] and
CVSS score is 9.8[2].

We need to update it to version 5.4+.

[1]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14343
[2]: https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?name=CVE-2020-14343&vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&version=3.1&source=NIST

Signed-off-by: Jintao Zhang <zhangjintao9020@gmail.com>
@tzssangglass tzssangglass merged commit a2882dc into apache:master Feb 27, 2022
@tao12345666333 tao12345666333 deleted the upgrade-pyyaml branch February 27, 2022 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants