9.8
CVSS V3
Status
Justification
Impact
Upstream patched _sha3 module with the XKCP fix for CVE-2022-37454, reference:- https://github.com/python/cpython/pull/98519. Additionally, if linking Python 3.10 against OpenSSL 1.1.1 or later, the OpenSSL provided sha3 implementation will be used instead of the vulnerable bundled _sha3 XKCP module code. Reference:- https://github.com/python/cpython/issues/98517#issuecomment-1287317496
Status