Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: CRLF injection in urllib3 - bump its version #5078

Closed
wants to merge 1 commit into from

Conversation

aviadatsnyk
Copy link

@aviadatsnyk aviadatsnyk commented May 2, 2019

https://app.snyk.io/vuln/SNYK-PYTHON-URLLIB3-174323 (CVE-2019-11236) is CRLF injection a vulnerability in the urllib3 library.
This PR bumps its version.
This might not be directly related to requests, but would forbid projects using requests from using a fixed version of urllib3

https://app.snyk.io/vuln/SNYK-PYTHON-URLLIB3-174323 (CVE-2019-11236) is CRLF injection a vulnerability in the urllib3 library.
This PR bumps its version.
@michael-k
Copy link
Contributor

See eg. discussions in kennethreitz/requests#5063, kennethreitz/requests#5065, kennethreitz/requests#5067

@aviadatsnyk
Copy link
Author

closing since this is already being discussed. sorry for the noise.

@aviadatsnyk aviadatsnyk closed this May 2, 2019
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Aug 31, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants