Skip to content

Security vulnerability in cryptography package #385

@rkpattnaik780

Description

@rkpattnaik780

Describe the Bug

The cryptography package v40.0.2 imported in Codeflare SDK has security vulnerabilties identified from the quay security scan.

Codeflare Stack Component Versions

Please specify the component versions in which you have encountered this bug.

Codeflare SDK: 0.9.0

Screenshots, Console Output, Logs, etc.

CVE | Severity | Package | Current version | Fixed in version
GHSA-jm77-qphf-c4w8 | Unknown | cryptography | 40.0.2 | 41.0.3
GHSA-5cpq-8wj7-hf2v | Unknown | cryptography | 40.0.2 | 41.0.0
GHSA-v8gr-m533-ghj9 | Unknown | cryptography | 40.0.2 | 41.0.4

Link to quay

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions