-
Notifications
You must be signed in to change notification settings - Fork 134
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SNYK Scan Finding: pyopenssl - Resource Exhaustion #4591
Comments
there's currently no fix for this issue yet although some work had been done previously. both are accounted for in catalog and inventory via snyk files. exp dates have been updated. |
Update per GSA/data.gov#4591, still no fix.
still no fix |
Still no fix. |
No fix until now |
Moving to Feb '25 mileston due to no fix |
Remediation available: |
The fix is to use pyopenSSL version greater than 24.0.0. |
Please keep any sensitive details in Google Drive.
Date of report: 2024-01-16
Severity: Moderate
Due date: 2024-04-26
Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.
* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.
Brief description
https://security.snyk.io/vuln/SNYK-PYTHON-PYOPENSSL-6157250
The text was updated successfully, but these errors were encountered: