Python Forum
what version has the fix for the CVEs?
Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
what version has the fix for the CVEs?
#12
I can't offer you much advice on this, but my thoughts are that if you mess with the install of jython2.7.2 you will, as likely as not, break something, so if I were to offer any advice at all, it would be to leave well alone unless you know what you're doing, and why.

This CVE is for the urllib3 package (primarily). If you are concerned about the possibility of an exploit and the impact of that, then report it to whom ever is responsible for the security of the network. If that person is you and you can't see a fix for this, then I'd question the use of jython2.7.2 as a whole, if an exploit is a real possibility and is a danger to the users of the computer network.
Sig:
>>> import this

The UNIX philosophy: "Do one thing, and do it well."

"The danger of computers becoming like humans is not as great as the danger of humans becoming like computers." :~ Konrad Zuse

"Everything should be made as simple as possible, but not simpler." :~ Albert Einstein
Reply


Messages In This Thread
RE: what version has the fix for the CVEs? - by rob101 - Nov-11-2022, 10:02 AM

Forum Jump:

User Panel Messages

Announcements
Announcement #1 8/1/2020
Announcement #2 8/2/2020
Announcement #3 8/6/2020