Azure / azure-uamqp-python

AMQP 1.0 client library for Python
MIT License
55 stars 47 forks source link

Vulnerable to CVE-2024-21646? #372

Closed risicle closed 5 months ago

risicle commented 5 months ago

The vendored copy of azure-uamqp-c is allegedly from 2021, so should we assume it's vulnerable to CVE-2024-21646?

kashifkhan commented 5 months ago

Hi @risicle, I have a PR out to pull in the patches and am running the tests for it behind the scenes. Im hoping to get it released next and will update this issue

kashifkhan commented 5 months ago

the new uaqmp version is now on pypi :)

risicle commented 5 months ago

Awesome thanks.

Could you tag the 1.6.7 release in github please? :D

kashifkhan commented 5 months ago

@risicle updated