Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk: Med Severity] Multiple Pillow vulnerabilities (Due: 09/07/2020) #3886

Closed
lbeaufort opened this issue Jul 9, 2020 · 0 comments · Fixed by #3990
Closed

[Snyk: Med Severity] Multiple Pillow vulnerabilities (Due: 09/07/2020) #3886

lbeaufort opened this issue Jul 9, 2020 · 0 comments · Fixed by #3990
Assignees
Labels
Security: moderate Remediate within 60 days
Milestone

Comments

@lbeaufort
Copy link
Member

lbeaufort commented Jul 9, 2020

Summary

  Pin Pillow@6.2.2 to Pillow@7.0.1 or upgrade Wagtail to fix
  ✗ Out-of-Bounds (new) [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-PILLOW-574573] in Pillow@6.2.2
    introduced by wagtail@2.7.2 > Pillow@6.2.2
  ✗ Out-of-bounds Read (new) [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-PILLOW-574574] in Pillow@6.2.2
    introduced by wagtail@2.7.2 > Pillow@6.2.2
  ✗ Out-of-bounds Read (new) [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-PILLOW-574575] in Pillow@6.2.2
    introduced by wagtail@2.7.2 > Pillow@6.2.2
  ✗ Out-of-bounds Read (new) [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-PILLOW-574576] in Pillow@6.2.2
    introduced by wagtail@2.7.2 > Pillow@6.2.2
  ✗ Buffer Overflow (new) [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-PILLOW-574577] in Pillow@6.2.2
    introduced by wagtail@2.7.2 > Pillow@6.2.2

WIP PR but tests fail: https://github.com/fecgov/fec-cms/pull/new/feature/3886-update-wagtail

Technical considerations

@lbeaufort lbeaufort added the Security: moderate Remediate within 60 days label Jul 9, 2020
@lbeaufort lbeaufort added this to the Sprint 13.3 milestone Jul 9, 2020
@lbeaufort lbeaufort changed the title [Snyk: Med Severity] Multiple Pillow vulnerabilityies (Due: 09/07/2020) [Snyk: Med Severity] Multiple Pillow vulnerabilities (Due: 09/07/2020) Jul 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: moderate Remediate within 60 days
Projects
None yet
2 participants