Summary: | dev-python/dask: unexpectedly listens on external interfaces (CVE-2021-42343) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | normal | CC: | cluster, mgorny, python |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://docs.dask.org/en/latest/changelog.html | ||
Whiteboard: | B2 [ebuild?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() For the record, I think we're not affected since we lastrited distributed long time ago. However, I suppose some users may readd it locally. I suspect the following commit in dask/distributed fixes it: commit afce4be8e05fb180e50a9d9e38465f1a82295e1b Author: Jim Crist-Harif <jcrist@users.noreply.github.com> Date: 2021-10-14 23:21:56 +0200 Pass `host` through `LocalCluster` to workers (#5427) Previously the `host` parameter to `LocalCluster` would only be forwarded to `Scheduler` instances and not `Worker`/`Nanny` instances, leading to workers listening on non-localhost in some configurations. This fixes that and adds a test. Co-authored-by: James Bourbeau <jrbourbeau@gmail.com> This is included in distributed 2021.10.0 but as I said, we don't package that anymore. Thanks, this can be invalid then. I asked MITRE about the useless references anyway, but haven't gotten a response. |