-
Notifications
You must be signed in to change notification settings - Fork 109
Closed
Labels
Security: moderateRemediate within 60 daysRemediate within 60 days
Milestone
Description
Vulnerable module: PyYAML
Introduced through: [email protected] › [email protected] › [email protected] Removed
Introduced through: [email protected] › [email protected] › [email protected] › [email protected]
Introduced through: [email protected] › [email protected] › [email protected]
No current remediation path. Best choice is to see what we can swap out for other packages or remove.
After discussing with @vrajmohan and putting in an issue to apispec to address the PyYAML vulnerability, our best approach is to:
- Update the dependent packages to the latest versions: Upgrade to latest apispec and flask-apispec versions #3356
- Fork the packages and use
yaml.safe_load()and use those forked versions in our project - Update
apispecto the latest version if they make the change
Metadata
Metadata
Assignees
Labels
Security: moderateRemediate within 60 daysRemediate within 60 days