This repository was archived by the owner on May 20, 2022. It is now read-only.
Commit f9f5c68
committed
requirements: update 'urllib3'
Closes #11.
Fix security vulnerabilities:
- [CVE-2019-11324](https://nvd.nist.gov/vuln/detail/CVE-2019-11324):
The urllib3 library before 1.24.2 for Python mishandles certain cases where
the desired set of CA certificates is different from the OS store of CA
certificates, which results in SSL connections succeeding in situations where
a verification failure is the correct outcome. This is related to use of the
`ssl_context`, `ca_certs`, or `ca_certs_dir` argument.
- [CVE-2019-9740](https://nvd.nist.gov/vuln/detail/CVE-2019-9740):
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in
Python 3.x through 3.7.2. CRLF injection is possible if the attacker controls
a url parameter, as demonstrated by the first argument to
`urllib.request.urlopen` with `\r\n` followed by an HTTP header or a Redis
command.
Changelog:
- 1.24.3 (2019-05-01)
https://github.com/urllib3/urllib3/blob/1.24.3/CHANGES.rst#1243-2019-05-01
Code diff:
urllib3/urllib3@1.24.1...1.24.31 parent d7d6a44 commit f9f5c68
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
0 commit comments