vchinnipilli / kubestriker

A Blazing fast Security Auditing tool for Kubernetes
https://github.com/vchinnipilli/kubestriker
Apache License 2.0
980 stars 106 forks source link

PyYAML < 5.4 (CVE-2020-14343) #15

Closed fabaff closed 3 years ago

fabaff commented 3 years ago

There is an issue with PyYAML 5.4 fixes CVE-2020-14343, see https://github.com/yaml/pyyaml/blob/5.4.1/CHANGES

https://github.com/vchinnipilli/kubestriker/blob/80051038c07b883dff2584f1eee6c45446f4249f/requirements.txt#L8

see also #14

vasantchinnipilli commented 3 years ago

Hi @fabaff Thank you for identifying and creating this issue. As requested, I will make the necessary changes and release a new version at the earliest.

Cheers,

fabaff commented 3 years ago

Hmmm, this was closed but I don't see a commit that sets a later PyYAML release.