Skip to content

Update pip cryptography to 39.0.2 (CVE-2023-0286 & CVE-2023-23931)

High
AzorianMatt published GHSA-6c8m-4h29-hmmh Mar 19, 2023

Package

pip cryptography (pip)

Affected versions

<39.0.1

Patched versions

None

Description

Summary

This is a simple requirements.txt version update for cryptography to version 39.0.2 to fix CVE-2023-0286 & CVE-2023-23931.

Details

CVE-2023-0286 & CVE-2023-23931 is fixed in cryptography 39.0.1, version 36.0.2 was being pinned in requirements.txt.

Impact

Possible impact to cryptographic functions in OAuth and maybe others, unlikely but possible.

I read the cryptography changelog and it appears the only real breaking changes is the requirement on OpenSSL/LibreSSL version.

No impact to requirements.txt installation on distributions.

Screenshot_20230318_221657

Severity

High
7.4
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

CVE ID

No known CVE

Weaknesses

No CWEs

Credits