This repository has been archived by the owner on Mar 11, 2024. It is now read-only.
CVE-2023-23931 (Medium) detected in cryptography-35.0.0-cp36-abi3-manylinux_2_24_x86_64.whl #44
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-23931 - Medium Severity Vulnerability
Vulnerable Library - cryptography-35.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
cryptography is a package which provides cryptographic recipes and primitives to Python developers.
Library home page: https://files.pythonhosted.org/packages/7b/1a/bf49bade5080a5cfb226a975c118fc56c3df2878b91809a5030dd87e551b/cryptography-35.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
Path to dependency file: /tmp/ws-scm/kalel
Path to vulnerable library: /tmp/ws-scm/kalel
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions
Cipher.update_into
would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such asbytes
) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present sinceupdate_into
was originally introduced in cryptography 1.8.Publish Date: 2023-02-07
URL: CVE-2023-23931
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-23931
Release Date: 2023-02-07
Fix Resolution: 39.0.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: