Safety vulnerability ID: 25876
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Lemur 0.1.5 includes a fix for CVE-2015-7764: Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
http://www.openwall.com/lists/oss-security/2015/10/20/3
https://github.com/Netflix/lemur/issues/117
https://github.com/kvesteri/sqlalchemy-utils/issues/166
Latest version: 1.8.2
Certificate management and orchestration service
~~~~~~~~~~~~~~~~~~
* **SECURITY ISSUE**: Switched from use a AES static key to Fernet encryption.
Affects all versions prior to 0.1.5. If upgrading this will require a data migration.
see: `Upgrading Lemur <https://lemur.readthedocs.com/adminstrationUpgradingLemur>`_
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application