Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve CVE for PyYAML - CVE-2020-14343 #2252

Closed
axsaucedo opened this issue Aug 7, 2020 · 2 comments · Fixed by #2891
Closed

Resolve CVE for PyYAML - CVE-2020-14343 #2252

axsaucedo opened this issue Aug 7, 2020 · 2 comments · Fixed by #2891
Labels
security Pull requests that address a security vulnerability
Milestone

Comments

@axsaucedo
Copy link
Contributor

Report here
Redhat report here

WIP in pyaml project

@axsaucedo axsaucedo added security Pull requests that address a security vulnerability triage Needs to be triaged and prioritised accordingly labels Aug 7, 2020
@axsaucedo axsaucedo added this to the 1.3 milestone Aug 7, 2020
@ukclivecox ukclivecox removed the triage Needs to be triaged and prioritised accordingly label Aug 13, 2020
@ukclivecox ukclivecox modified the milestones: 1.3, 1.4 Aug 20, 2020
@axsaucedo
Copy link
Contributor Author

Currently being worked as part of PYYAML 5.4 https://github.com/yaml/pyyaml/projects/5

@axsaucedo axsaucedo modified the milestones: 1.4, 1.5 Oct 15, 2020
@ukclivecox ukclivecox modified the milestones: 1.5, 1.6 Nov 30, 2020
@axsaucedo
Copy link
Contributor Author

This has now been resolved and is part of the latest release, so will add a task to upgrade to latest pyyaml for the next sprint yaml/pyyaml#420

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants