-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
Problem
urllib3
vulnerability .Trivy complains about the following version 1.26.11 due to GHSA-v845-jxx5-vc9f. Note the link below currently yields a 404
😒 .
Library | Vulnerability | Severity | Installed Version | Fixed Version | Title |
---|---|---|---|---|---|
urllib3 | CVE-2023-43804 | MEDIUM | 1.26.11 | 2.0.6, 1.26.17 | Cookie HTTP header isn't stripped on cross-origin redirects https://avd.aquasec.com/nvd/cve-2023-43804 |
Anything Else?
It looks like this is being addressed in #3180 Is this close to being in a merge-able state?
jbmoorhouse, mattelen, BabOuDev, albieduffy and HubertBosolliemath and jbmoorhouse
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file