fedora-cloud / docker-brew-fedora

MIT License
176 stars 46 forks source link

Paramiko introducing multiple vulnerabilities in dependencies for cryptography component #111

Open huornlmj opened 1 year ago

huornlmj commented 1 year ago

CVE-2023-0286, CVE-2023-23931, GHSA-39hc-v87j-747x, CVE-2023-38325 and GHSA-5cpq-8wj7-hf2v are being introduced to the fedora:38 image when the OS paramiko package is installed as it brings in the cryptography component. The vulerabilities are not present when the cryptography Python package is installed itself.