Executive brief
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
Affected products
- PyPI cryptography
Junglewise Threat Intelligence
CVE-2023-38325 · Severity: low · CVSS 3.1 · Published 2023-07-14
Technologies: cryptography (PyPI). Vendors: PyPI.
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.