Skip to content

cryptography pin to 38.0.1 includes CVE-2023-0286 #26210

@dsteeley

Description

@dsteeley

Being flagged for CVE-2023-0286 which is included by azure-cli Linux package install.

https://github.com/Azure/azure-cli/blame/dev/src/azure-cli/requirements.py3.Linux.txt#L98

Could you please investigate bumping this version to resolve the CVE?

The version was bumped but then reverted in f345be6, is there a ticket tracking resolving why the latest version of cryptography isn't used?

Metadata

Metadata

Assignees

Labels

Auto-AssignAuto assign by botAzure CLI TeamThe command of the issue is owned by Azure CLI teamInstallationcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.feature-request

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions