Skip to content

(fix) urllib3 update for CVE vulnerabilities#221

Open
bigjimmynz wants to merge 3 commits intoaws-solutions:mainfrom
bigjimmynz:main
Open

(fix) urllib3 update for CVE vulnerabilities#221
bigjimmynz wants to merge 3 commits intoaws-solutions:mainfrom
bigjimmynz:main

Conversation

@bigjimmynz
Copy link

Using AWS Security Hub, it reported CVE vulnerabilities in 2 Lambda functions (State Machine, Lifecycle Event processor).

GHSA-gm62-xv2j-4w53
GHSA-2xpw-w6gg-jr37
GHSA-38jv-5279-wg99

This is in the urllib3 library which is used by boto3 and botocore. This is specified in the setup.py file during build time. Which will generate new zip files for the Lambda functions.

Contributing to Customizations for AWS Control Tower (CfCT).

Thank you for your interest in contributing to Customizations for AWS Control Tower (CfCT).

At this time, we are not accepting contributions. If contributions are accepted in the future, Customizations for AWS Control Tower (CfCT) is released under the Apache license and any code submitted will be released under that license.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants