Safety vulnerability ID: 52585
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Automatoes 0.9.7 updates its dependency 'cryptography' to v3.4.4 to include a security fix.
Latest version: 0.9.13
Let's Encrypt/ACME V2 client replacement for Manuale. Manual or automated your choice.
Feb 20, 2020
We are pleased to announce the release of Automatoes 0.9.7.
This is a security fix that address CVE-2020-36242 updating cryptography to a
patched version.
We still support python 3.5 but the cryptography being installed won't be
patched against CVE-2020-36242.
It is recommended to upgrade your Python version as Python 3.5 is no longer
maintained (end of life was September 13th, 2020) and cryptography dropped
python 3.5 support.
Here are the highlights:
Security
* CVE-2020-36242: Symmetrically encrypting large values can lead to integer overflow 84
Bugs
* Suppress crypto.py warning on Python 3.5 83
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application