-
Notifications
You must be signed in to change notification settings - Fork 172
Closed
Labels
bugSoftware defect or bugSoftware defect or bugcomplianceRelating to security compliance or documentationRelating to security compliance or documentation
Milestone
Description
Please keep any sensitive details in Google Drive.
Date of report: 2025-05-02
Severity: High
Due date: 2025-06-02
Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.
- Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)
* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.
Brief description
https://security.snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606
Upgrade setuptools@71.0.4 to setuptools@78.1.1 to fix
✗ Directory Traversal (new) [High Severity][https://security.snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606] in setuptools@71.0.4
introduced by setuptools@71.0.4 and 5 other path(s)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSoftware defect or bugSoftware defect or bugcomplianceRelating to security compliance or documentationRelating to security compliance or documentation
Type
Projects
Status
🗄 Closed