-
-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update minimatch to fix vulnerability CVE-2016-10540 [1.x] #100
Comments
I have updated the issue title. When you say "images" I think of photos, not of Docker images. :-) (I am not the right person to fix this issue though.) |
There should be an updated plone.staticresources at the end of the Plone 6 UI sprint end this week/early next week. |
Thank you both @mauritsvanrees @thet (Yeah, context matters. I've been "swimming in the Docker pool" for the past several weeks and so "image" and "container" have taken on entirely new meanings for me 😅) |
For Plone 6 this can be closed ... should there be a security patch for Plone 5.2 ? |
I unfortunately have to ship Plone to government sites which use the Twistlock scanner to check Docker images for vulnerabilities.
Plone 5.2.2's
plone.staticresources-1.3.2
includes one such vulnerability: CVE-2016-10540. The issue is thatminimatch
is at version 0.3.0, but should be ≥ 3.0.2.The data from Twistlock is:
RegExp
objects. The primary function,minimatch(path, pattern)
in Minimatch 3.0.1 and earlier is vulnerable to ReDoS in thepattern
parameter.The text was updated successfully, but these errors were encountered: