Vulnerability DatabaseGHSA-h4gh-qq45-vh27

GHSA-h4gh-qq45-vh27
Python vulnerability analysis and mitigation

Overview

A moderate severity vulnerability (GHSA-h4gh-qq45-vh27) was identified in pyca/cryptography versions 37.0.0 through 43.0.0. The issue stems from the statically linked copy of OpenSSL included in cryptography wheels, which contains a security vulnerability. This vulnerability was published and reviewed on September 3, 2024, affecting the pip package cryptography (GitHub Advisory).

Technical details

The underlying vulnerability (CVE-2024-6119) in OpenSSL involves applications performing certificate name checks that may attempt to read an invalid memory address when comparing the expected name with an otherName subject alternative name of an X.509 certificate. This issue specifically affects basic certificate validation processes. The vulnerability is present in OpenSSL versions 3.0, 3.1, 3.2, and 3.3, though FIPS modules in these versions are not affected (OpenSSL Advisory).

Impact

The vulnerability can result in abnormal termination of the application process, potentially causing a denial of service. This primarily affects applications performing certificate name checks, such as TLS clients checking server certificates. The impact is particularly relevant when applications specify an expected DNS name, Email address, or IP address (OpenSSL Advisory).

Mitigation and workarounds

Users are advised to upgrade to cryptography version 43.0.1 or later. For those building cryptography from source (sdist), they are responsible for upgrading their copy of OpenSSL. Only users installing from wheels built by the cryptography project (distributed on PyPI) need to update their cryptography versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management