Invalid XML security version
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 35/100
Línea de trabajo
Revisa el tratamiento de la seguridad de #618, el contexto de release de #621 y #613, y el debate sobre el versionado de #590; después, inspecciona el aviso de PyUp enlazado en la issue. Se considera hecho cuando el aviso identifica 4.4.5 como la versión mínima segura sin requerir el release 4.5.0 no validado, y se han comprobado las advertencias de dependencias resultantes.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Description
Since the introduction of #621 and release 4.5.0 in #613, tools that track security/dependency updates like pyup are flagging the following:
An XML external entity (XXE) injection in PyWPS before 4.5.0 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected. See CVE-2021-39371.
from:
https://pyup.io/repos/github/crim-ca/weaver/commits/?page=1#a586cb79de278fdc33d6eeee5feb6f6233f60a16
Because XML security specific to that issue was handled in #618, which is tagged after in 4.4.5, the requirement should be injection in PyWPS before 4.4.5, an mark the minimum requirement as 4.4.5 rather than 4.5.0.
I would like to have a revision of the security advisory for the lower version for 2 reasons:
- Version
4.5.0introduces some important changes relative toogc-api, which are not trivial to guarantee backward compatibility with existing services that did not expect them to be there. - According to whichever decision taken from #590, the
4.5.xbranch should be either a development branch until4.6.xor addition ofogc-apishould introduce5.xreleases. Either way,4.5.0is not a "ready" release (as shown by tests still failing), and suggesting users to fix the XML security should not be done at the same time as new features integration.
Currently, I am receiving a lot of warnings regarding this security issue, and I cannot directly/safely update to 4.5.0 yet until it is properly validated.
- Lenguaje dominante
- Python
- Estrellas
- 186
- Forks
- 117
- Merge medio
- 11 d 20 h
- PR fusionados (30 d)
- 1
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de geopython/pywps
-
ReadTheDocs OAuth App InstallationQuizá libre de nuevo @tomkralidis la tomó hace 70 días y no hay ningún pull request abierto. Abiertodocumentation
-
Modernizing the packaging of the libraryQuizá libre de nuevo @Zeitsperre la tomó hace 283 días y no hay ningún pull request abierto. Abiertodocumentation enhancement packaging
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 45/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
-
ComplexOutput data as reference always generates a file named "input.csv", should be "output".Abierto
Dificultad 3/5 1-2 días Aptitud para principiantes 35/100
Todos los issues de geopython/pywps
Issues similares
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
workflow: a tick's dispatch counts as 'only this step', and no review self-grants a round unattendedAbiertoworkflow
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
kristofdegrave/homeassistant-smart-charging#1505 ·
Los mantenedores suelen responder en 1 día
-
New Submission: TropWATERAbiertometadata submission
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
Wrongly named dashboard variableAbiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
canonical/content-cache-operator#163 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[submission]Abiertosubmission
Dificultad 1/5 Menos de una hora Aptitud para principiantes 65/100
leanprover/lean-eval-submissions#1852 ·
Los mantenedores suelen responder en 1 día