GHSA-h4gh-qq45-vh27

Suggest an improvement
Source
https://github.com/advisories/GHSA-h4gh-qq45-vh27
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-h4gh-qq45-vh27/GHSA-h4gh-qq45-vh27.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h4gh-qq45-vh27
Related
Published
2024-09-03T21:59:48Z
Modified
2024-09-03T22:21:42.270402Z
Summary
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Details

pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt.

If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.

References

Affected packages

PyPI / cryptography

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
37.0.0
Fixed
43.0.1

Affected versions

37.*

37.0.0
37.0.1
37.0.2
37.0.3
37.0.4

38.*

38.0.0
38.0.1
38.0.2
38.0.3
38.0.4

39.*

39.0.0
39.0.1
39.0.2

40.*

40.0.0
40.0.1
40.0.2

41.*

41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7

42.*

42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8

43.*

43.0.0