Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in cryptography package #385

Open
rkpattnaik780 opened this issue Oct 20, 2023 · 0 comments
Open

Security vulnerability in cryptography package #385

rkpattnaik780 opened this issue Oct 20, 2023 · 0 comments

Comments

@rkpattnaik780
Copy link

Describe the Bug

The cryptography package v40.0.2 imported in Codeflare SDK has security vulnerabilties identified from the quay security scan.

Codeflare Stack Component Versions

Please specify the component versions in which you have encountered this bug.

Codeflare SDK: 0.9.0

Screenshots, Console Output, Logs, etc.

CVE | Severity | Package | Current version | Fixed in version
GHSA-jm77-qphf-c4w8 | Unknown | cryptography | 40.0.2 | 41.0.3
GHSA-5cpq-8wj7-hf2v | Unknown | cryptography | 40.0.2 | 41.0.0
GHSA-v8gr-m533-ghj9 | Unknown | cryptography | 40.0.2 | 41.0.4

Link to quay

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant