Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pyaml reference to 4.1+ to avoid Arbitrary Code Execution issues. #4193

Closed
SeppPenner opened this issue May 30, 2019 · 2 comments
Closed
Labels
guidance Question that needs advice or information.

Comments

@SeppPenner
Copy link

SeppPenner commented May 30, 2019

The currently used PyYAML@3.13 contains a Arbitrary Code Execution issue. Check https://app.snyk.io/vuln/SNYK-PYTHON-PYYAML-42159 and https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18342 for more information.

@ViktorHaag
Copy link

ViktorHaag commented May 30, 2019

This is likely a duplicate issue. There is a PR in flight that would cover this already.

See also issues:

It seems logical to close this issue to avoid adding confusion and further duplication, and potentially adding the info-references you posted here to another issue's comments?

@SeppPenner SeppPenner changed the title Updated pyaml reference to 4.1+ to avoid Arbitrary Code Execution issues. Update pyaml reference to 4.1+ to avoid Arbitrary Code Execution issues. May 30, 2019
@SeppPenner
Copy link
Author

It seems logical to close this issue to avoid adding confusion and further duplication, and potentially adding the info-references you posted here to another issue's comments?

I agree with you. I haven't seen the other issues while searching... I added the information to two of the other issues.

@justnance justnance added the guidance Question that needs advice or information. label May 31, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
guidance Question that needs advice or information.
Projects
None yet
Development

No branches or pull requests

3 participants