Description
cryptography mishandles SSH certificates
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 pypi | | | 41.0.2 |
 alpine v3.23 | | =0.6.1-r0 || =0.8.2-r0 || =1.0.2-r0 || =1.3.1-r0 || =1.3.2-r0 || =1.4-r0 || =1.4-r1 || =1.4-r2 || =1.5.2-r0 || =1.5.2-r1 || =1.5.3-r0 || =1.7.2-r0 || =1.7.2-r1 || =1.8.1-r0 || =1.8.1-r1 || =1.9-r0 || =2.0.2-r0 || =2.0.3-r0 || =2.0.3-r1 || =2.1.3-r0 || =2.1.4-r0 || =2.1.4-r1 || =2.2.2-r0 || =2.3.1-r0 || =2.3.1-r1 || =2.4.2-r0 || =2.4.2-r1 || =2.4.2-r2 || =2.5-r0 || =2.6.1-r0 || =2.6.1-r1 || =2.7-r0 || =2.7-r1 || =2.8-r0 || =2.8-r1 || =2.9-r0 || =2.9.2-r0 || =3.2.1-r0 || =3.3-r0 || =3.3.1-r0 || =3.3.2-r0 || =3.3.2-r1 || =3.3.2-r2 || =3.3.2-r3 || =3.3.2-r4 || =3.4.8-r0 || =3.4.8-r1 || =37.0.4-r0 || =37.0.4-r1 || =37.0.4-r2 || =38.0.1-r0 || =38.0.2-r0 || =38.0.3-r0 || =38.0.3-r1 || =38.0.4-r0 || =39.0.0-r0 || =39.0.1-r0 || =39.0.2-r0 || =40.0.0-r0 || =40.0.1-r0 || =40.0.2-r0 || =40.0.2-r1 || =41.0.0-r0 || =41.0.1-r0 || >=0 <41.0.2-r0 | 41.0.2-r0 |