Skip to content

Commit d80186a

Browse files
committed
test/docker: security analysis of GHSA-cq46-m9x9-j8w2 for scapy
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
1 parent f8e62fb commit d80186a

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

test/docker/pip-requirements.txt

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,8 @@ pydot==1.4.2
66
pyyaml==6.0.1
77
passlib==1.7.4
88
requests~=2.32.4
9+
# GHSA-cq46-m9x9-j8w2: scapy <=2.6.1 has pickle deserialization vuln in session
10+
# loading (-s flag). Low risk: test framework only uses packet crafting (Ether,
11+
# sendp, LLDP), not session loading. Update to 2.7.0+ when available on PyPI.
12+
# https://github.com/advisories/GHSA-cq46-m9x9-j8w2
913
scapy==2.6.1

0 commit comments

Comments
 (0)