You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Mar 20, 2024. It is now read-only.
Cut an easy_sast release with these updated requirements.
Based on the breaking changes introduced since the last release, this will be version 1.0.0 (see git log 'v0.2.0'...'0eefbb341facfdd5cfe73774faebdb311579d232' --oneline).
The text was updated successfully, but these errors were encountered:
Summary
snyk.io is currently reporting that the version of
pyyaml
used byeasy_sast
is vulnerable to an Arbitrary Code Execution vulnerability.easy_sast
was never susceptible to this vulnerability, as it has always usedsafe_load
which is considered safe. MITRE has assigned this vulnerability CVE-2020-1747.Potential Impact
There is no impact to the
easy_sast
project due to the appropriate use ofsafe_load
to load untrusted yaml files.pyyaml
is used for configuration loading (pyyaml
5.3), and the testing (pyyaml
5.3) of configuration loading.Next Steps
easy_sast
requirements viamake requirements
when Prevents arbitrary code execution during python/object/new constructor yaml/pyyaml#386 is merged and included in a release.easy_sast
release with these updated requirements.1.0.0
(seegit log 'v0.2.0'...'0eefbb341facfdd5cfe73774faebdb311579d232' --oneline
).The text was updated successfully, but these errors were encountered: