You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@beam.apache.org by "Kenneth Knowles (Jira)" <ji...@apache.org> on 2022/01/16 14:21:00 UTC
[jira] [Updated] (BEAM-10180) Upgrade httplib2 to > 0.18.0 to resolve CVE-2020-11078
[ https://issues.apache.org/jira/browse/BEAM-10180?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Kenneth Knowles updated BEAM-10180:
-----------------------------------
Fix Version/s: 2.30.0
Assignee: Ahmet Altay
Resolution: Fixed
Status: Resolved (was: Triage Needed)
> Upgrade httplib2 to > 0.18.0 to resolve CVE-2020-11078
> ------------------------------------------------------
>
> Key: BEAM-10180
> URL: https://issues.apache.org/jira/browse/BEAM-10180
> Project: Beam
> Issue Type: Improvement
> Components: sdk-py-core
> Reporter: Jay Crumb
> Assignee: Ahmet Altay
> Priority: P3
> Fix For: 2.30.0
>
>
> In versions of httplib2 before 0.18.0, an attacker who could control the url provided to {{httplib2.Http.request()}} could modify the request's headers or body.
>
> As I understand from looking at BEAM-9819 the current restriction exists because of a dependency on google-apitools so this may not be a straightforward fix.
>
> CVE: [https://nvd.nist.gov/vuln/detail/CVE-2020-11078]
> GitHub Advisory: [https://github.com/advisories/GHSA-gg84-qgv9-w4pq]
> Release Notes: https://github.com/httplib2/httplib2/blob/master/CHANGELOG#L7
--
This message was sent by Atlassian Jira
(v8.20.1#820001)