CVE-2023-38325 is a high-severity vulnerability affecting the cryptography package for Python, specifically versions prior to 41.0.2, where it improperly handles SSH certificates with critical options. This flaw allows an unauthenticated attacker to achieve high integrity impact remotely with low attack complexity, although it does not affect confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 40.0.0, < 41.0.2CPE matchmatch criteria | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-38325
Jun 11, 2024python-cryptography: SSH certificate encoding/parsing incompatibility with OpenSSH
Jul 15, 2023cryptography mishandles SSH certificates
Jul 14, 2023The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
Jul 11, 2023