Skip to content

Fix possible fix(deps): 4 vulnerable dependencies in requirements.txt - #637

Open
begininvoke wants to merge 1 commit into
ProjectASAP:mainfrom
begininvoke:redgem/security-fix-180ac6b6
Open

Fix possible fix(deps): 4 vulnerable dependencies in requirements.txt#637
begininvoke wants to merge 1 commit into
ProjectASAP:mainfrom
begininvoke:redgem/security-fix-180ac6b6

Conversation

@begininvoke

Copy link
Copy Markdown

Small change to asap-tools/experiments/requirements.txt — a scan flagged the code below and it looked genuine. It is around line 3.

CVE‑2024‑56201 in Jinja2 <3.1.5 lets an attacker who controls both the template filename and its contents break out of Jinja's sandbox and execute arbitrary Python code. When an application processes untrusted templates where the template author can also set the filename (e.g., uploaded templates with chosen names), this can lead to remote code execution. The risk is medium‑high because exploitation requires both content and filename control, but when those conditions are met the impact is severe.

Update dependencies to patch known security vulnerabilities: Jinja2, hydra-core, and msgpack.

For reference: rule CVE-2024-56201. Rated high.

Take or leave whichever parts are useful. If this is not the right approach, closing is fine.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant