Skip to content

PYSEC-2023-241 specifies vulnerable versions that are not actually vulnerable #251

@cswimr

Description

@cswimr

The description for PYSEC-2023-241 says that it was resolved in Piccolo 1.1.1. Yet, the vulnerable versions listed in that file include versions after 1.1.1. May not be related, may be related, not really sure how this works, but the osv.dev listing for the same vulnerability marks that all Piccolo versions are vulnerable to this issue, despite it being patched in 1.1.1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions