TCGstorageAPI icon indicating copy to clipboard operation
TCGstorageAPI copied to clipboard

CVE-2023-50782 (High) detected in cryptography-3.3.2-cp36-abi3-manylinux2010_x86_64.whl

Open mend-for-github-com[bot] opened this issue 1 year ago • 0 comments

CVE-2023-50782 - High Severity Vulnerability

Vulnerable Library - cryptography-3.3.2-cp36-abi3-manylinux2010_x86_64.whl

cryptography is a package which provides cryptographic recipes and primitives to Python developers.

Library home page: https://files.pythonhosted.org/packages/c6/d1/800ec785c9e66cc6d0ac587bd666eb22f7b2ff6c150e053d35881acd2f57/cryptography-3.3.2-cp36-abi3-manylinux2010_x86_64.whl

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

  • :x: cryptography-3.3.2-cp36-abi3-manylinux2010_x86_64.whl (Vulnerable Library)

Found in HEAD commit: 5d2716db3707839aa53c951b058fa0cc13d65dd8

Found in base branch: master

Vulnerability Details

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Publish Date: 2024-02-05

URL: CVE-2023-50782

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-3ww4-gg4f-jr7f

Release Date: 2024-02-05

Fix Resolution: 42.0.0


  • [ ] Check this box to open an automated fix PR