Sonatype OSS Index CVE #2745
-
There is an active CVE in Sonatype's OSS Index (https://ossindex.sonatype.org/vulnerability/sonatype-2021-0482?component-type=pypi&component-name=altair) connected to I'm working in an unfortunately restrictive environment and could not get an exception approved for |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 2 replies
-
Can you link the issue where this has been discussed? In 418sec/huntr#1942 the code injection is presented. |
Beta Was this translation helpful? Give feedback.
-
This should get you there: |
Beta Was this translation helpful? Give feedback.
-
Regardless true/false of this CVE within the current scope of Altair; are you allowed to install It might be good to eventually move from
If you prepare a pull request mentioning that the FullLoader is intended to be deprecated and replaced by SafeLoader then we can finish this discussion too. |
Beta Was this translation helpful? Give feedback.
Regardless true/false of this CVE within the current scope of Altair; are you allowed to install
pyyaml
? This vulnerability has been fixed upstream inpyyaml>=5.4
: https://github.com/yaml/pyyaml/blob/master/CHANGES#L27It might be good to eventually move from
yaml.FullLoader
toyaml.SafeLoader
for other reasons:If you prepare a pull request mentioning that the FullLoader is intended to be deprecated and replaced by SafeLoader then we can finish this discussion too.