Skip to content

[Snyk: High] arbitrary code execution (Due: 08/28/2020) #4525

@jason-upchurch

Description

@jason-upchurch

User story

as a user of openFEC, I want vulnerabilities to be patched.
https://app.snyk.io/vuln/SNYK-PYTHON-PYYAML-590151

Summary

A vulnerability is introduced through [email protected]:

in [email protected]
introduced by [email protected] > [email protected] and 2 other path(s)
  No upgrade or patch available

Completion criteria:

  • Confirm this is a problem and if so, determine whether there is an upgrade and make that change
  • If it's a confirmed vulnerability and if no remediation is available notify security

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions