Dependency starkbank-ecdsa forces high-severity vulnerability
envgap__sendgrid__sendgrid-python-1023
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
ab040cb25696a900224789cb2f97bbf5193fd307- Manifest
requirements.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
sendgrid/sendgrid-python #1023 · read the original issue
Github has alerted us that our project has a high-severity vulnerability `starkbank-ecdsa` version 1.1.1. The requirements file here forces us to install it (see `requirements.txt`): ``` starkbank-ecdsa>=1.0.0,<2.0.0 ``` Please fix this so we don't have to install this library to use sendgrid. From the github alert: ``` GHSA-9wx7-jrvc-28mm high severity Vulnerable versions: < 2.0.1 Patched version: 2.0.1 An attacker can forge signatures on arbitrary messages that will verify for any public key. This may allow attackers to authenticate as any user within the Stark Bank platform, and bypass signature verification needed to perform operations on the platform, such as send payments and transfer funds. Additionally, the ability for attackers to forge signatures may impact other users and projects using these libraries in different and unforeseen ways. ``` PS - what does it use this library anyway? Seems odd that an email library depends on bank software.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]