Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

python-3.9-bookworm and python-3.9-bullseye vulnerable to CVE-2022-40897 #900

Closed
dserodio opened this issue Jan 19, 2024 · 3 comments
Closed

Comments

@dserodio
Copy link

Library Vulnerability Severity Status Installed Version Fixed Version Title
setuptools (METADATA) CVE-2022-40897 HIGH fixed 58.1.0 65.5.1 pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
https://avd.aquasec.com/nvd/cve-2022-40897
@ad-m-ss
Copy link

ad-m-ss commented Jan 19, 2024

We rarely update the tools versions from what is included in the given python release (#781 (comment)) since that often can be breaking changes.

@ad-m-ss
Copy link

ad-m-ss commented Jan 19, 2024

Oh, there are three duplicate issues #879 , #782, #781 for CVE-2022-40897.

Could we ensure to search for duplicates before creating a new issue?

@dserodio
Copy link
Author

Oh, there are three duplicate issues #879 , #782, #781 for CVE-2022-40897.

Could we ensure to search for duplicates before creating a new issue?

Sorry about that, I only looked at the open issues before reporting 😞

@tianon tianon closed this as completed Jan 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants