Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-201-4160 Vulnerability Is Found in Lib/site-packages/cryptography/hazmat/bindings/_openssl.pyd for Cryptography Version 3.3.2 #90924

Closed
zjmxq mannequin opened this issue Feb 16, 2022 · 1 comment
Labels
3.9 only security fixes stdlib Python modules in the Lib dir type-security A security issue

Comments

@zjmxq
Copy link
Mannequin

zjmxq mannequin commented Feb 16, 2022

BPO 46768
Nosy @tiran

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = <Date 2022-02-16.16:29:20.094>
created_at = <Date 2022-02-16.12:57:14.015>
labels = ['type-security', 'library', '3.9']
title = 'CVE-201-4160 Vulnerability Is Found in Lib/site-packages/cryptography/hazmat/bindings/_openssl.pyd for Cryptography Version 3.3.2'
updated_at = <Date 2022-02-16.16:29:20.090>
user = 'https://bugs.python.org/zjmxq'

bugs.python.org fields:

activity = <Date 2022-02-16.16:29:20.090>
actor = 'christian.heimes'
assignee = 'none'
closed = True
closed_date = <Date 2022-02-16.16:29:20.094>
closer = 'christian.heimes'
components = ['Library (Lib)']
creation = <Date 2022-02-16.12:57:14.015>
creator = 'zjmxq'
dependencies = []
files = []
hgrepos = []
issue_num = 46768
keywords = []
message_count = 1.0
messages = ['413339']
nosy_count = 2.0
nosy_names = ['christian.heimes', 'zjmxq']
pr_nums = []
priority = 'normal'
resolution = 'third party'
stage = 'resolved'
status = 'closed'
superseder = None
type = 'security'
url = 'https://bugs.python.org/issue46768'
versions = ['Python 3.9']

@zjmxq zjmxq mannequin added 3.9 only security fixes stdlib Python modules in the Lib dir type-security A security issue labels Feb 16, 2022
@tiran
Copy link
Member

tiran commented Feb 16, 2022

The file is from 3rd party package PyCA cryptography and not maintained by us. 3.3.2 is an old version of cryptography and no longer supported. I recommend that you update to cryptography 36.0.1

@tiran tiran closed this as completed Feb 16, 2022
@tiran tiran closed this as completed Feb 16, 2022
@ezio-melotti ezio-melotti transferred this issue from another repository Apr 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.9 only security fixes stdlib Python modules in the Lib dir type-security A security issue
Projects
None yet
Development

No branches or pull requests

1 participant