Hi team,
In a security scan I got the following vulnerability "CVE-2023-23931", the affected package is "cryptography".
Looking into the change log (https://cryptography.io/en/latest/changelog/#v39-0-1), found that the vulnerability was fixed in the following version:
39.0.1 - 2023-02-07
-
SECURITY ISSUE - Fixed a bug where Cipher.update_into accepted Python buffer protocol objects, but allowed immutable buffers. CVE-2023-23931
-
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.8.
Looking into the available package of "cryptography" in the Aix Tool box (AIX Toolbox for Open Source Software : Downloads alpha
| Ibm |
remove preview |
|
| AIX Toolbox for Open Source Software : Downloads alpha |
| AIX Toolbox for Open Source Software contains a collection of open source and GNU software built for AIX IBM Systems. These tools provide the basis of the development environment of choice for many Linux application developers. |
| View this on Ibm > |
|
|
)
The latest version is the following:

Is there a plan to deliver a new version of "cryptography" to fix the vulnerability?
------------------------------
LUIS ABDEL AGUILAR JURADO
------------------------------
#AIXOpenSource