Tempest was using: -python module xml.etree[1], It was vulnerable to different atacks. Instead of xml.etree.ElementTree tempest is now using defusedxml.ElementTree which is more secure. [1] https://bandit.readthedocs.io/en/1.7.0/blacklists/blacklist_calls.html B313 Change-Id: I50a8ab3c3be2decccd7480ecf00f1a3e4a75f172changes/33/859833/4
parent
4ff6f153b1
commit
76db176c7e
Loading…
Reference in new issue