Closed
Description
Hello! We got a security vulnerability warning in our builds due to our dependency on future 0.18.2
.
- pyup report: https://pyup.io/vulnerabilities/CVE-2022-40899/52510/
- MITRE CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40899
- GitHub Advisory: GHSA-v3c5-jqr6-7qm8
Desciption:
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
The report has a link to pull request to fix a similar issue in cpython.
python/cpython#17157
Metadata
Metadata
Assignees
Labels
No labels