Azure / azure-uamqp-python

AMQP 1.0 client library for Python
MIT License
57 stars 47 forks source link

Vulnerable to CVE-2024-21646? #372

Closed risicle closed 10 months ago

risicle commented 10 months ago

The vendored copy of azure-uamqp-c is allegedly from 2021, so should we assume it's vulnerable to CVE-2024-21646?

kashifkhan commented 10 months ago

Hi @risicle, I have a PR out to pull in the patches and am running the tests for it behind the scenes. Im hoping to get it released next and will update this issue

kashifkhan commented 10 months ago

the new uaqmp version is now on pypi :)

risicle commented 10 months ago

Awesome thanks.

Could you tag the 1.6.7 release in github please? :D

kashifkhan commented 10 months ago

@risicle updated