Skip to content

July PyPI Vulnerabilities#29

Merged
ewdurbin merged 8 commits into
vstinner:mainfrom
di:july-vulnz
Jul 29, 2021
Merged

July PyPI Vulnerabilities#29
ewdurbin merged 8 commits into
vstinner:mainfrom
di:july-vulnz

Conversation

@di
Copy link
Copy Markdown
Contributor

@di di commented Jul 28, 2021

(cc @ewdurbin)

Copy link
Copy Markdown

@pradyunsg pradyunsg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Content looks great! I only have non-blocking nit-picky concerns. :)

Comment on lines +5 to +7
An exploitable vulnerability in the mechanisms for deleting legacy
documentation hosting deployment tooling on `PyPI <https://pypi.org>`_ was
discovered by a security researcher, which would allow an attacker to remove documentation for projects not under their control.
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Let's either wrap this at a specific line, or not wrap this at all. 🙈

following guidelines in security policy on `pypi.org
<https://pypi.org/security/>`_)
* 2021-07-26 (**+1days**): Fix is implemented and deployed in `commit 33ad32
<https://github.com/pypa/warehouse/commit/33ad326aab676b74bde3ecad686cf144e8c98fc9>`_
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: some references use the URLs of the form:

https://github.com/pypa/warehouse/commit/33ad326aab676b74bde3ecad686cf144e8c98fc9

while others use:

https://github.com/pypa/warehouse/pull/9846/commits/50bd16422889d653127d373c9615516bf883a394

Let's use the former, uniformly throughout?

@di
Copy link
Copy Markdown
Contributor Author

di commented Jul 28, 2021

@pradyunsg Added you as a collaborator on my fork if you'd like to push those changes.

Copy link
Copy Markdown
Contributor

@Ry0taK Ry0taK left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Leaving some reviews. Thank you so much for the write-up!

Comment thread pypi-vuln/index-2021-07-27-role-deletion.rst Outdated
Comment thread pypi-vuln/index-2021-07-27-combine-prs-workflow.rst Outdated
Comment thread pypi-vuln/index-2021-07-26-legacy-document-deletion.rst
Comment thread pypi-vuln/index-2021-07-27-combine-prs-workflow.rst Outdated
Comment thread pypi-vuln/index-2021-07-27-combine-prs-workflow.rst Outdated
Co-authored-by: RyotaK <49341894+Ry0taK@users.noreply.github.com>
Comment thread pypi-vuln/index-2021-07-27-combine-prs-workflow.rst Outdated
Comment thread pypi-vuln/index-2021-07-27-role-deletion.rst Outdated
@ewdurbin ewdurbin merged commit cb96e45 into vstinner:main Jul 29, 2021
@ewdurbin ewdurbin deleted the july-vulnz branch July 29, 2021 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants