Skip to content

SNOW-2442924 bump requests to 2.32.4 to fix CVE-2024-47081#105

Closed
sfc-gh-dszmolka wants to merge 1 commit intosnowflakedb:masterfrom
sfc-gh-dszmolka:SNOW-2442924-bump-requests-CVE-2024-47081
Closed

SNOW-2442924 bump requests to 2.32.4 to fix CVE-2024-47081#105
sfc-gh-dszmolka wants to merge 1 commit intosnowflakedb:masterfrom
sfc-gh-dszmolka:SNOW-2442924-bump-requests-CVE-2024-47081

Conversation

@sfc-gh-dszmolka
Copy link

Description

https://nvd.nist.gov/vuln/detail/CVE-2024-47081 is fixed with requests>=2.32.4 . Ideally, we should bump to latest 2.32.5, but it dropped Python 3.8 support (as it should, it's EOL..) - but we still only require Python 3.4 as a minimum runtime here.

So to avoid breaking people who still possibly use this library on Python 3.8 (allowed by this library), not bumping to latest but the latest which has the CVE fixed. We can figure out Python dependency requirements separately.

@sfc-gh-hdang
Copy link
Contributor

Somehow the github actions fail. Recreated a PR which doesn't have the issue: #106

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants