PT-2022-28180 · Pyca · Cryptography

Published

2022-11-02

·

Updated

2022-11-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions cryptography versions 37.0.0 through 38.0.3
Description The issue concerns the statically linked copy of OpenSSL in pyca/cryptography's wheels. The included versions of OpenSSL are affected by several security issues, details of which can be found in the official OpenSSL security advisory.
Recommendations For cryptography versions 37.0.0 through 38.0.3, update to a version outside of this range to resolve the issue. If you are building cryptography from source, upgrade your copy of OpenSSL to a secure version.

Related Identifiers

GHSA-39HC-V87J-747X

Affected Products

Cryptography