CVE-2023-49083 (High) detected in cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl, cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl #63
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-49083 - High Severity Vulnerability
Vulnerable Libraries - cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl, cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
cryptography is a package which provides cryptographic recipes and primitives to Python developers.
Library home page: https://files.pythonhosted.org/packages/b2/26/7af637e6a7e87258b963f1731c5982fb31cd507f0d90d91836e446955d02/cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
Path to dependency file: /tmp/ws-scm/JsMERG
Path to vulnerable library: /JsMERG
Dependency Hierarchy:
cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
cryptography is a package which provides cryptographic recipes and primitives to Python developers.
Library home page: https://files.pythonhosted.org/packages/4c/a2/6565c5271a79e3c96d7a079053b4d8408a740d4bf365f0f5f244a807bd09/cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
Path to dependency file: /requirements.txt
Path to vulnerable library: /requirements.txt
Dependency Hierarchy:
Found in HEAD commit: b766c4aafc268281f97cb694accb8ab77070c150
Found in base branch: main
Vulnerability Details
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling
load_pem_pkcs7_certificates
orload_der_pkcs7_certificates
could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.Publish Date: 2023-11-29
URL: CVE-2023-49083
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-49083
Release Date: 2023-11-29
Fix Resolution: 41.0.6
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: