CASMCMS-8714/CASMCMS-8715: Fix CVEs in cfs-ara and cfs-operator #2588
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary and Scope
CASMCMS-8714
Snyk reported that cfs-ara is vulnerable to this CVE:
https://security.snyk.io/vuln/SNYK-PYTHON-DJANGO-5750790
This updates cfs-ara to a version where the Django module is pinned to a version with this CVE fixed.
CASMCMS-8715
Snyk reported that cfs-operator is vulnerable to this CVE:
https://security.snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5777683
This updates cfs-operator to a version where the cryptography module is pinned to a version with this CVE fixed.
Issues and Related PRs
release/1.4 backport manifest PR
stable/1.5 backport manifest PR
release/1.6 backport manifest PR
Resolves CASMCMS-8714
Resolves CASMCMS-8715
cfs-ara
source PRcfs-operator
source PR