Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Snyk finding: SNYK-PYTHON-WERKZEUG-8309092 #4951

Open
1 task done
FuhuXia opened this issue Oct 28, 2024 · 0 comments
Open
1 task done

Snyk finding: SNYK-PYTHON-WERKZEUG-8309092 #4951

FuhuXia opened this issue Oct 28, 2024 · 0 comments
Labels
bug Software defect or bug compliance Relating to security compliance or documentation
Milestone

Comments

@FuhuXia
Copy link
Member

FuhuXia commented Oct 28, 2024

https://security.snyk.io/vuln/SNYK-PYTHON-WERKZEUG-8309092

Date of report: 2024-10-28
Severity: Medium
Due date: 2025-01-28

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

Upgrade Werkzeug to version 3.0.6 or higher.
CKAN 2.11.0 is using 3.0.3.

@FuhuXia FuhuXia added compliance Relating to security compliance or documentation bug Software defect or bug labels Oct 28, 2024
@FuhuXia FuhuXia added this to the January 2025 milestone Oct 28, 2024
@Bagesary Bagesary moved this to 🧊 Icebox in data.gov team board Oct 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Software defect or bug compliance Relating to security compliance or documentation
Projects
Status: 🧊 Icebox
Development

No branches or pull requests

1 participant