ansible-operator
Chainguard
5.3
CVSS V3
Status
Impact
Upgrading requests to the fix version requires upstream maintainers to implement compatibility. More information can be found in the following PR: https://github.com/operator-framework/ansible-operator-plugins/pull/92#issuecomment-2352324292
Status
Justification
Impact
py3-pip installs a patched version of 2.32.3 requests.py which contains the upstream fix for CVE-2024-47081, reference https://github.com/wolfi-dev/os/pull/55998/files. The version referenced in the vendor.txt is not vulnerable
Status