PyPi: Oci

CVE-2023-23931

Transitive

Safety vulnerability ID: 53764

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 07, 2023 Updated at Oct 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Oci 2.95.0 updates its dependency 'cryptography' to include a security fix.

Affected package

oci

Latest version: 2.137.1

Oracle Cloud Infrastructure Python SDK

Affected versions

Fixed versions

Vulnerability changelog

====================

Added
-----
* Support for the Identity Domains service
* Support for long-term backups for autonomous databases on Exadata Cloud at Customer in the Database service
* Support for database OS patching in the Database service
* Support for managing enhanced clusters, cluster add-ons, and serverless virtual node pools in the Container Engine for Kubernetes service
* Support for templates and copy object requests in the Data Integration service
* Support for maintenance features in the GoldenGate service
* Support for AMD_MILAN_BM_GPU configuration type on instances in the Compute service
* Support for host storage metrics and network metrics as part of host capacity planning in the Operations Insights service

Breaking
--------
* `UNKNOWN_ENUM_VALUE` will be returned for unknown enum values, instead of raising `ValueError`, for property `protocol` in model `IdentityProvider` in the Identity Data Plane service
* `UNKNOWN_ENUM_VALUE` will be returned for unknown enum values, instead of raising `ValueError`, for property `lifecycle_state` in model `TemplateSummary` in the Identity Data Plane service

Security
--------
* The upper bound for `cryptography` dependency has changed to versions less than `40.0.0` to address security vulnerability CVE-2023-23931. For more discussion please see https://github.com/oracle/oci-python-sdk/issues/515

====================

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 6.5

CVSS v3 Details

MEDIUM 6.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
NONE
Integrity Impact (I)
LOW
Availability Availability (A)
LOW