Skip to content

Conversation

gsnyder2007
Copy link
Contributor

Two methods, upload_scan and download_project_scans, used hardcoded values (False) for the verify parameter used by the requests module to enforce secure (SSL) connections. The corrections here take the value from a configuration file that the user (of blackduck library) uses to specify whether to enforce secure connections or not.

@gsnyder2007 gsnyder2007 requested a review from mkumykov October 22, 2020 18:50
Copy link
Contributor

@mkumykov mkumykov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It will keep it consistent. Nice

@mkumykov mkumykov merged commit 0a25777 into master Oct 22, 2020
@james-otten
Copy link

Known as CVE-2020-27589

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants