[go: up one dir, main page]

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Selenium 4.2.0 Version Vulnerability #2720

Open
cbarrett3 opened this issue Dec 28, 2023 · 2 comments
Open

Selenium 4.2.0 Version Vulnerability #2720

cbarrett3 opened this issue Dec 28, 2023 · 2 comments
Assignees
Labels
bug something broken infrastructure build process etc. P3 backlog sev-1 blocker

Comments

@cbarrett3
Copy link
cbarrett3 commented Dec 28, 2023

Selenium Version Vulnerability: selenium>=3.141.0,<=4.2.0

using dash 2.14.2

Describe the bug

We are using Synk to scan the dependencies of our project, which is using the latest version of dash. The Synk scan is showing these vulnerabilities (Snyk: CVSS 7.5 NVD: CVSS 7.5), as a result of the selenium version being kept below 4.2.0 here.

Expected behavior

We expect there not to be open high vulnerabilities in the dash application - although they are only exposed through testing.

A suggestion is that this dependency on selenium is either upgraded, or removed from the client-facing installation.

@Coding-with-Adam Coding-with-Adam added infrastructure build process etc. P1 needed for current cycle labels Jan 3, 2024
@Coding-with-Adam Coding-with-Adam added sev-1 blocker and removed P1 needed for current cycle labels Jan 18, 2024
@tscheburaschka
Copy link

I am also hit by this upper boundary on the selenium version. Is there a particular reason for this?

@gvwilson
Copy link
Contributor

cc @mike-sol

@gvwilson gvwilson added P3 backlog bug something broken labels Aug 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug something broken infrastructure build process etc. P3 backlog sev-1 blocker
Projects
None yet
Development

No branches or pull requests

5 participants