Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-35255: Upgrade azure-identity to v1.16.1 #1663

Open
gnuletik opened this issue Aug 27, 2024 · 0 comments
Open

CVE-2024-35255: Upgrade azure-identity to v1.16.1 #1663

gnuletik opened this issue Aug 27, 2024 · 0 comments
Labels
bug Something isn't working potential Unconfirmed issue

Comments

@gnuletik
Copy link

The azure-identity dependency is locked to v1.5.0.
This version of the dependency is vulnerable to privilege escalation.

Can it be upgraded?

There is a Dependabot PR already open: #1646

Refs:

Thanks!

@gnuletik gnuletik added bug Something isn't working potential Unconfirmed issue labels Aug 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working potential Unconfirmed issue
Projects
None yet
Development

No branches or pull requests

1 participant