faraday is vulnerable to Race Condition
18
Low Risk
Affected versions of this package are vulnerable to a thread safety issue in the proxy option of Faraday, where the provided hash is mutated by adding keys to it. In multi-threaded environments, this can lead to a RuntimeError. The fix avoids modifying the original hash by working with a duplicate instead and includes a test to ensure the original proxy option remains unchanged.
You are affected if you are using a version that falls within the vulnerable range.
faraday is vulnerable to Race Condition in versions 0.15.3 - 2.12.2.
Upgrade the faraday library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant