Re: [Cryptography-dev] Request to remediate vulnerabilities

2023-03-07 Thread Paul Kehrer
3.4.7 was released 2021-03-25. Since that time we've had 18 releases. Why would you ask for a patch without looking to see if we have newer versions? We also document our support policy (main branch and latest release) under our security page: https://cryptography.io/en/latest/security/#supported-v

Re: [Cryptography-dev] Request to remediate vulnerabilities

2023-03-07 Thread Alex Gaynor
This issue is resolved in cryptography version 39.0.1 and newer. You simply need to upgrade. Alex On Tue, Mar 7, 2023 at 6:02 AM Mani Sankar Karanam via Cryptography-dev wrote: > > Hello Team !!! > Thank you for providing the open source python package cryptography. It is > greatly helpful to u

[Cryptography-dev] Request to remediate vulnerabilities

2023-03-07 Thread Mani Sankar Karanam via Cryptography-dev
Hello Team !!! Thank you for providing the open source python package *cryptography*. It is greatly helpful to us. We are currently using *cryptography* of version* 3.4.7*. It has below Common Vulnerabilities and Exposures(CVEs) associated with it. CVE-2023-23931 Can you please remediate them in t