Skip to content

bump cookiecutter version to address CVE#3956

Merged
hawflau merged 5 commits intoaws:developfrom
hawflau:bump-cookiecutter-version
Jun 16, 2022
Merged

bump cookiecutter version to address CVE#3956
hawflau merged 5 commits intoaws:developfrom
hawflau:bump-cookiecutter-version

Conversation

@hawflau
Copy link
Contributor

@hawflau hawflau commented Jun 10, 2022

The package cookiecutter before 2.1.1 is vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.

Bumping cookiecutter version to address the CVE.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@hawflau hawflau enabled auto-merge (squash) June 10, 2022 00:19
@hawflau hawflau disabled auto-merge June 10, 2022 06:59
@hawflau hawflau merged commit 1b2b2fd into aws:develop Jun 16, 2022
@hawflau hawflau deleted the bump-cookiecutter-version branch June 23, 2022 19:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants