Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cryptography<41.0.3 includes vulnerable OpenSSL version #19

Closed
mnbf9rca opened this issue Sep 16, 2023 · 1 comment · Fixed by #20
Closed

cryptography<41.0.3 includes vulnerable OpenSSL version #19

mnbf9rca opened this issue Sep 16, 2023 · 1 comment · Fixed by #20

Comments

@mnbf9rca
Copy link
Contributor

see Vulnerable OpenSSL included in cryptography wheels and pyca/cryptography's wheels include vulnerable OpenSSL

python-dotenv-vault depends on cryptography<41.0.0,>=3.1.0 which prevents package managers resolving a higher version e.g.:

(venv) @mnbf9rca ➜ /workspace (chore/update_deps) $ poetry add cryptography@>=41.0.3

Because python-dotenv-vault (0.6.3) depends on cryptography (>=3.1.0,<41.0.0)
 and no versions of python-dotenv-vault match >0.6.3,<0.7.0, python-dotenv-vault (>=0.6.3,<0.7.0) requires cryptography (>=3.1.0,<41.0.0).
So, because mqtt-to-eventhub depends on both python-dotenv-vault (^0.6.3) and cryptography (^41.0.3), version solving failed.
mnbf9rca added a commit to mnbf9rca/mqtt-to-eventhub that referenced this issue Sep 16, 2023
@mnbf9rca
Copy link
Contributor Author

additional High severity CVE-2023-38325 which would require cryptography>41.0.2 to resolve

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant