gitlab-cng-fips-18.6
Chainguard
6.3
CVSS V3
Status
Impact
The cryptography dependency at version 43.0.3 contains a vulnerability that is fixed in 44.0.1. This is a transitive dependency brought in by PyOpenSSL and cannot be directly overridden (cryptography<44,>=41.0.5 from PyOpenSSL). Resolution requires upstream PyOpenSSL to update cryptography to version 44.0.1+.
Status