Use of a Risky Cryptographic Algorithm Affecting cryptography package, versions [,1.5.2)
Threat Intelligence
EPSS
0.4% (75th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-CRYPTOGRAPHY-40445
- published 1 Nov 2016
- disclosed 1 Nov 2016
- credit Markus Rudy
Introduced: 1 Nov 2016
CVE-2016-9243 Open this link in a new tabOverview
cryptography
provides cryptographic recipes and primitives to Python developers.
Affected versions of this package are vulnerable to Use of a Risky Cryptographic Algorithm. HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size
.
References
CVSS Scores
version 3.1