Описание
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
Отчет
OpenSSH certificate parsing was introduced in python-cryptography v40.0.0 and fixed in upstream release v41.0.2. Since, Red Hat Enterprise Linux - 7, 8, 9 ships lower versions of python-cryptography (releases < v40.0.0), those are not affected by this CVE.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | ansible-tower | Not affected | ||
Red Hat Ansible Automation Platform 2 | ansible-lint | Not affected | ||
Red Hat Ansible Automation Platform 2 | ansible-navigator | Not affected | ||
Red Hat Ansible Automation Platform 2 | automation-controller | Not affected | ||
Red Hat Ansible Automation Platform 2 | python3x-ansible-compat | Not affected | ||
Red Hat Ansible Automation Platform 2 | python3x-cryptography | Not affected | ||
Red Hat Ansible Automation Platform 2 | python-ansible-compat | Not affected | ||
Red Hat Ansible Automation Platform 2 | python-cryptography | Not affected | ||
Red Hat Certification for Red Hat Enterprise Linux 6 | redhat-certification-backend | Not affected | ||
Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification-baremetal-container | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2231271python-cryptography: SSH certificate encoding/parsing incompatibility with OpenSSH
EPSS
Процентиль: 71%
0.00706
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 2 года назад
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVSS3: 7.5
nvd
почти 2 года назад
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVSS3: 7.5
debian
почти 2 года назад
The cryptography package before 41.0.2 for Python mishandles SSH certi ...
EPSS
Процентиль: 71%
0.00706
Низкий
7.5 High
CVSS3