Safety vulnerability ID: 37415
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Oci version 2.0.2 includes a fix for CVE-2018-10903: A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Latest version: 2.137.1
Oracle Cloud Infrastructure Python SDK
====================
Added
-----
* Support for the Limits service
* Support for archiving to Object Storage in the Streaming service
* Support for etags on resources in the Streaming service
* Support for Key Management service (KMS) encryption of file systems in the File Storage service
* Support for moving public IP, DHCP, local peering gateway, internet gateway, network security group, and DRG attachment resources across compartments in the Networking service
* Support for multi-origin, basic cache, certificate mapping, and OCI Monitoring service integration in the Web Application Acceleration and Security service
====================
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application