Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-38325 #8077

Closed
tooptoop4 opened this issue Aug 3, 2023 · 2 comments
Closed

CVE-2023-38325 #8077

tooptoop4 opened this issue Aug 3, 2023 · 2 comments
Assignees
Labels
bug This issue is a bug.

Comments

@tooptoop4
Copy link

Describe the bug

pip3 install https://github.com/aws/aws-cli/archive/refs/tags/2.13.6.tar.gz

Installed Resource
cryptography 40.0.1

Fixed Version
41.0.2

Expected Behavior

high cve gone with new cryptography

Current Behavior

high cve

Reproduction Steps

install latest v2

Possible Solution

No response

Additional Information/Context

No response

CLI version used

2.13.6

Environment details (OS name and version, etc.)

unix

@tooptoop4 tooptoop4 added bug This issue is a bug. needs-triage This issue or PR still needs to be triaged. labels Aug 3, 2023
@tim-finnigan tim-finnigan self-assigned this Aug 3, 2023
@tim-finnigan
Copy link
Contributor

Hi @tooptoop4 thanks for reaching out. I brought this up for discussion with the team, and they wanted me to highlight that the AWS CLI should not be affected by this CVE as it does not use the cryptography package for SSH certificates. There is a dependabot PR (#8030) raising the version ceiling for cryptography and we recommend tracking that for updates going forward. The team is currently blocked on merging that PR pending further review.

@tim-finnigan tim-finnigan removed the needs-triage This issue or PR still needs to be triaged. label Aug 3, 2023
@github-actions
Copy link

github-actions bot commented Aug 3, 2023

⚠️COMMENT VISIBILITY WARNING⚠️

Comments on closed issues are hard for our team to see.
If you need more assistance, please open a new issue that references this one. If you wish to keep having a conversation with other community members under this issue feel free to do so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug This issue is a bug.
Projects
None yet
Development

No branches or pull requests

2 participants