PyPi: Edumfa

CVE-2024-56201

Transitive

Safety vulnerability ID: 74991

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 23, 2024 Updated at Mar 27, 2025
Scan your Python projects for vulnerabilities →

Advisory

Edumfa version 2.6.0 has updated its jinja2 dependency from version 3.1.4 to 3.1.5 to address a critical security vulnerability identified as CVE-2024-56201.

Affected package

edumfa

Latest version: 2.7.2

eduMFA: identity, multifactor authentication (OTP), authorization, audit

Affected versions

Fixed versions

Vulnerability changelog

What's Changed

> [!CAUTION]
>
> As mentioned in the previous release this version does no longer support Python 3.8!
>

* chore: add support for python 3.13 by fritterhoff in https://github.com/eduMFA/eduMFA/pull/357
* chore: drop support for Python 3.8 by Luc1412 in https://github.com/eduMFA/eduMFA/pull/384
* docs: add healthcheck for Mariadb by johanneskastl in https://github.com/eduMFA/eduMFA/pull/476
* fix: add check to exec user scripts only if scripts are available by fbmei in https://github.com/eduMFA/eduMFA/pull/474
* fix: extract uv requirement per token by fritterhoff in https://github.com/eduMFA/eduMFA/pull/501
* fix: use format string for last auth timestamp by j-hoff in https://github.com/eduMFA/eduMFA/pull/494
* chore(deps): update dependency certifi to v2024.12.14 by renovate in https://github.com/eduMFA/eduMFA/pull/477
* chore(deps): update dependency charset-normalizer to v3.4.1 by renovate in https://github.com/eduMFA/eduMFA/pull/486
* chore(deps): update dependency click to v8.1.8 by renovate in https://github.com/eduMFA/eduMFA/pull/482
* chore(deps): update dependency croniter to v6 by renovate in https://github.com/eduMFA/eduMFA/pull/479
* chore(deps): update dependency cryptography to v44 by renovate in https://github.com/eduMFA/eduMFA/pull/441
* chore(deps): update dependency flask-migrate to v4.1.0 by renovate in https://github.com/eduMFA/eduMFA/pull/500
* chore(deps): update dependency google-auth to v2.37.0 by renovate in https://github.com/eduMFA/eduMFA/pull/475
* chore(deps): update dependency grpcio to v1.69.0 by renovate in https://github.com/eduMFA/eduMFA/pull/490
* chore(deps): update dependency jinja2 to v3.1.5 [security] by renovate in https://github.com/eduMFA/eduMFA/pull/485
* chore(deps): update dependency pyopenssl to v25 by renovate in https://github.com/eduMFA/eduMFA/pull/502
* chore(deps): update dependency python-gnupg to v0.5.4 by renovate in https://github.com/eduMFA/eduMFA/pull/495
* chore(deps): update dependency setuptools to v75.8.0 by renovate in https://github.com/eduMFA/eduMFA/pull/496
* chore(deps): update dependency sqlalchemy to v2.0.37 by renovate in https://github.com/eduMFA/eduMFA/pull/498
* chore(deps): update dependency urllib3 to v2.3.0 by renovate in https://github.com/eduMFA/eduMFA/pull/484
* chore(deps): update python docker tag to v3.13 by renovate in https://github.com/eduMFA/eduMFA/pull/355
* fix(deps): update dependency attrs to v24.3.0 by renovate in https://github.com/eduMFA/eduMFA/pull/478
* fix(deps): update dependency coverage to v7.6.10 by renovate in https://github.com/eduMFA/eduMFA/pull/487
* fix(deps): update dependency pygments to v2.19.1 by renovate in https://github.com/eduMFA/eduMFA/pull/493
* fix(deps): update dependency pyparsing to v3.2.1 by renovate in https://github.com/eduMFA/eduMFA/pull/489
* fix(deps): update dependency responses to v0.25.5 by renovate in https://github.com/eduMFA/eduMFA/pull/499
* fix(deps): update dependency sphinxcontrib-spelling to v8.0.1 by renovate in https://github.com/eduMFA/eduMFA/pull/480
* fix(deps): update dependency types-pyyaml to v6.0.12.20241230 by renovate in https://github.com/eduMFA/eduMFA/pull/488

New Contributors
* johanneskastl made their first contribution in https://github.com/eduMFA/eduMFA/pull/476

**Full Changelog**: https://github.com/eduMFA/eduMFA/compare/v2.5.0...v2.6.0

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application