nutanix.ansible icon indicating copy to clipboard operation
nutanix.ansible copied to clipboard

[Imprv] Update python setuptools to mitigate GHSA-r9hx-vwmv-q579

Open kenmoini opened this issue 1 year ago • 1 comments

Describe the request The current pinned version of setuptools in requirements.txt is vulnerable to a RegExDoS as defined here in this CVE: https://nvd.nist.gov/vuln/detail/CVE-2022-40897

Current behaviour It works, though container image scans produce High impact rating vulnerability reports.

Expected behaviour Pass container image scans when included in an execution environment.

kenmoini avatar Oct 30 '23 14:10 kenmoini

I believe it was fixed by setuptools in : https://github.com/pypa/setuptools/issues/3659 Assigning to @Gevorg-Khachatryan-97

bhati-pradeep avatar Nov 17 '23 11:11 bhati-pradeep