Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerability in tap-chargebee dependency urllib3 #108

Open
benw-at-birdie opened this issue Apr 4, 2024 · 0 comments
Open

Critical vulnerability in tap-chargebee dependency urllib3 #108

benw-at-birdie opened this issue Apr 4, 2024 · 0 comments

Comments

@benw-at-birdie
Copy link

benw-at-birdie commented Apr 4, 2024

Hi there

Versions of urllib3 before version 1.23 have a critical vulnerability: https://nvd.nist.gov/vuln/detail/cve-2018-20060.

The current version of urllib installed by tap-chargebee is 1.22. Updating to the next minor version will fix the vulnerability. Is it possible to upgrade?

Kind regards
Ben

image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant