Skip to content

x/vulndb: potential Go vuln in github.com/pyca/cryptography: CVE-2023-38325 #1920

Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2023-38325 references github.com/pyca/cryptography, which may be a Go module.

Description:
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

References:

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/pyca/cryptography
      vulnerable_at: 0.0.0-20230714123722-04c4ea58b46a
      packages:
        - package: n/a
description: |-
    The cryptography package before 41.0.2 for Python mishandles SSH certificates
    that have critical options.
cves:
    - CVE-2023-38325
references:
    - report: https://github.com/pyca/cryptography/issues/9207
    - fix: https://github.com/pyca/cryptography/pull/9208
    - web: https://pypi.org/project/cryptography/#history
    - web: https://github.com/pyca/cryptography/compare/41.0.1...41.0.2

Metadata

Metadata

Assignees

Labels

excluded: NOT_GO_CODEThis vulnerability does not refer to a Go module.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions