Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk:Medium] requests Always-Incorrect Control Flow Implementation (Due: 08/19/2024) #6285

Closed
1 task
pkfec opened this issue May 22, 2024 · 0 comments · Fixed by #6366
Closed
1 task

[Snyk:Medium] requests Always-Incorrect Control Flow Implementation (Due: 08/19/2024) #6285

pkfec opened this issue May 22, 2024 · 0 comments · Fixed by #6366
Assignees
Labels
Security: moderate Remediate within 60 days
Milestone

Comments

@pkfec
Copy link
Contributor

pkfec commented May 22, 2024

Overview

Affected versions of this package are vulnerable to Always-Incorrect Control Flow Implementation when making requests through a Requests Session. An attacker can bypass certificate verification by making the first request with verify=False, causing all subsequent requests to ignore certificate verification regardless of changes to the verify value.

Introduced through:

[email protected]

Remediation:

upgrade requests to v2.32.0

Completion criteria:

  • upgrade requests to v2.32.0 and verify snyk cli no longer flags requests as vulnerable package
@pkfec pkfec added the Security: moderate Remediate within 60 days label May 22, 2024
@pkfec pkfec added this to the 25.5 milestone May 22, 2024
@tmpayton tmpayton moved this to 🔜 Sprint backlog in Website project Jul 3, 2024
@tmpayton tmpayton moved this from 🔜 Sprint backlog to 📥 Assigned in Website project Jul 9, 2024
@JonellaCulmer JonellaCulmer moved this from 📥 Assigned to 👀 Ready in Website project Jul 23, 2024
@JonellaCulmer JonellaCulmer modified the milestones: 25.5, 25.6 Jul 23, 2024
@github-project-automation github-project-automation bot moved this from 👀 Ready to ✅ Done in Website project Jul 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: moderate Remediate within 60 days
Projects
Status: ✅ Done
Development

Successfully merging a pull request may close this issue.

3 participants