Skip to content

chore(deps): update dependency gevent to v23 [security] - #340

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-gevent-vulnerability
Open

chore(deps): update dependency gevent to v23 [security]#340
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-gevent-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 25, 2023

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
gevent (changelog) ==21.12.0==23.9.0 age confidence

Gevent allows remote attacker to escalate privileges

CVE-2023-41419 / GHSA-x7m3-jprg-wc5g

More information

Details

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (in timezone Asia/Tehran)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the Dependencies Pull requests that update a dependency file label Sep 25, 2023
@renovate
renovate Bot force-pushed the renovate/pypi-gevent-vulnerability branch from 0b8557c to 8d2a11b Compare October 2, 2023 19:53
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2023

Copy link
Copy Markdown

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@renovate
renovate Bot force-pushed the renovate/pypi-gevent-vulnerability branch from 8d2a11b to 0b3ea03 Compare August 10, 2025 14:06
@sonarqubecloud

Copy link
Copy Markdown

@renovate renovate Bot changed the title chore(deps): update dependency gevent to v23 [security] chore(deps): update dependency gevent to v23 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/pypi-gevent-vulnerability branch March 27, 2026 04:37
@renovate renovate Bot changed the title chore(deps): update dependency gevent to v23 [security] - autoclosed chore(deps): update dependency gevent to v23 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-gevent-vulnerability branch 2 times, most recently from 0b3ea03 to 5597d44 Compare March 30, 2026 22:07
@sonarqubecloud

Copy link
Copy Markdown

@renovate renovate Bot changed the title chore(deps): update dependency gevent to v23 [security] chore(deps): update dependency gevent to v23 [security] - autoclosed Sep 1, 2026
@renovate renovate Bot closed this Sep 1, 2026
@renovate renovate Bot changed the title chore(deps): update dependency gevent to v23 [security] - autoclosed chore(deps): update dependency gevent to v23 [security] Sep 2, 2026
@renovate renovate Bot reopened this Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-gevent-vulnerability branch 2 times, most recently from 5597d44 to 488716b Compare September 2, 2026 21:28
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Development

Successfully merging this pull request may close these issues.

0 participants