PyPi: Compliance-Trestle

CVE-2023-50782

Transitive

Safety vulnerability ID: 65626

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 05, 2024 Updated at Dec 05, 2024
Scan your Python projects for vulnerabilities →

Advisory

Compliance-trestle version 2.6.0 upgrades its cryptography library to version 42.0.0 from 41.0.6 to mitigate the security issue CVE-2023-50782.
https://github.com/oscal-compass/compliance-trestle/pull/1509/commits/41c880a2122fc52820e6fcee6f1193fd937c0673

Affected package

compliance-trestle

Latest version: 3.6.0

Tools to manage & autogenerate python objects representing the OSCAL layers/models

Affected versions

Fixed versions

Vulnerability changelog

Feature
* Multiple parms per rule ([1499](https://github.com/oscal-compass/compliance-trestle/issues/1499)) ([`218ffe4`](https://github.com/oscal-compass/compliance-trestle/commit/218ffe47a879e8bbca115bd956cfc9e99bbc5751))

Fix
* Add multiple parameters per rule support on component definition ([1504](https://github.com/oscal-compass/compliance-trestle/issues/1504)) ([`96e3f02`](https://github.com/oscal-compass/compliance-trestle/commit/96e3f02fc597ded59ed11f5bd2b07aa2c0ccb504))
* Community call ([1516](https://github.com/oscal-compass/compliance-trestle/issues/1516)) ([`53d7fd4`](https://github.com/oscal-compass/compliance-trestle/commit/53d7fd484bdd42e22ff58e3244da732835c2cfea))
* Correct vulnerability ([1509](https://github.com/oscal-compass/compliance-trestle/issues/1509)) ([`4f70e0a`](https://github.com/oscal-compass/compliance-trestle/commit/4f70e0af0e4063ac3cd763ff0c7e319168c0d805))
* Add check for empty label to fix failure for statement with no label property ([1507](https://github.com/oscal-compass/compliance-trestle/issues/1507)) ([`55ed462`](https://github.com/oscal-compass/compliance-trestle/commit/55ed462107d577efc9099b8ed59c5718eee9e47c))

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 7.5

CVSS v3 Details

HIGH 7.5
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
NONE
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
NONE
Availability Availability (A)
NONE