VYPR

apk package

chainguard/py3-cassandra-medusa

pkg:apk/chainguard/py3-cassandra-medusa

Vulnerabilities (81)

  • CVE-2024-12797MedFeb 11, 2025
    affected < 0.23.0-r2fixed 0.23.0-r2

    Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode is set. Impact summary: TLS and DTLS connections u

  • CVE-2024-53899HigNov 24, 2024
    affected < 0.23.0-r0fixed 0.23.0-r0

    virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

  • CVE-2024-52304HigNov 18, 2024
    affected < 0.22.3-r1fixed 0.22.3-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions. If a pure Python version of ai

  • CVE-2024-42367MedAug 12, 2024
    affected < 0.22.3-r1fixed 0.22.3-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root director

  • CVE-2024-6345HigJul 15, 2024
    affected < 0.23.0-r30fixed 0.23.0-r30

    A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are suscepti

  • CVE-2024-3651HigJul 7, 2024
    affected < 0.23.0-r30fixed 0.23.0-r30

    A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service co

  • CVE-2024-39689HigJul 5, 2024
    affected < 0.23.0-r30fixed 0.23.0-r30

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes ro

  • CVE-2024-37891MedJun 17, 2024
    affected < 0.23.0-r30fixed 0.23.0-r30

    urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it'

  • CVE-2024-35255MedJun 11, 2024
    affected < 0.21.0-r3fixed 0.21.0-r3

    Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

  • CVE-2024-35195MedMay 20, 2024
    affected < 0.23.0-r30fixed 0.23.0-r30

    Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes

  • CVE-2024-27306MedApr 18, 2024
    affected < 0.20.1-r0fixed 0.20.1-r0

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files.

  • CVE-2024-26130HigFeb 21, 2024
    affected < 0.19.1-r1fixed 0.19.1-r1

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided

  • CVE-2023-50782HigFeb 5, 2024
    affected < 0.17.2-r1fixed 0.17.2-r1

    A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • CVE-2024-23829MedJan 29, 2024
    affected < 0.17.2-r1fixed 0.17.2-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to pr

  • CVE-2024-23334MedJan 29, 2024
    affected < 0.17.2-r1fixed 0.17.2-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether

  • CVE-2024-0727MedJan 26, 2024
    affected < 0.17.2-r1fixed 0.17.2-r1

    Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can c

  • CVE-2023-49081HigNov 30, 2023
    affected < 0.19.1-r1fixed 0.19.1-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability

  • CVE-2023-49082MedNov 29, 2023
    affected < 0.19.1-r1fixed 0.19.1-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerabilit

  • CVE-2023-49083MedNov 29, 2023
    affected < 0.19.1-r1fixed 0.19.1-r1

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious

  • CVE-2023-47627MedNov 14, 2023
    affected < 0.19.1-r1fixed 0.19.1-r1

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt whe

Page 4 of 5