|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-4068: python-pytest-html: the npm package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Security | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED UPSTREAM | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | daniel.garcia, gabriele.sonnu |
| Version: | Leap 15.6 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/405385/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-4068:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1224256 | ||
|
Description
SMASH SMASH
2024-05-16 11:57:20 UTC
A vulnerable version (3.0.2) of the braces package is embedded in: - openSUSE:Factory/python-pytest-html Upstream issue: https://github.com/micromatch/braces/issues/35 python-pytest-html braces dependency is as follow: 1. mocha -> chokidar -> braces 2. sass -> chokidar -> braces 1. mocha is used for tests, that we don't run, so can be removed, or even ignored. In any case there's an issue in chokidar about this and looks like the score is too high: https://github.com/paulmillr/chokidar/issues/1314 2. sass is not vulnerable: https://github.com/sass/dart-sass/issues/2243 So after this small analysis we can say that this package is not affected. Looks like there's a fix in braces upstream [1] to avoid this issue. There will be a new release soon. [1] https://github.com/micromatch/braces/pull/37 (In reply to Daniel Garcia from comment #2) > So after this small analysis we can say that this package is not affected. We can close this, then. |