QID 983477
QID 983477: Python (pip) Security Update for mitogen (GHSA-8rf6-w2mx-4xjh)
** DISPUTED ** core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8rf6-w2mx-4xjh for updates pertaining to this vulnerability.
Vendor References
- GHSA-8rf6-w2mx-4xjh -
github.com/advisories/GHSA-8rf6-w2mx-4xjh
CVEs related to QID 983477
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8rf6-w2mx-4xjh | mitogen |
|