Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Phyton (v3.12.6) vulnerabilities in NCPA agent v3.1.1 #1230

Open
barww opened this issue Dec 10, 2024 · 4 comments
Open

Phyton (v3.12.6) vulnerabilities in NCPA agent v3.1.1 #1230

barww opened this issue Dec 10, 2024 · 4 comments

Comments

@barww
Copy link

barww commented Dec 10, 2024

Reported vulnerabilities (CVE-2024-12254, CVE-2024-9287, CVE-2024-50602) against Phyton v3.12.6 which is included in NCPA agent v3.1.1 (the current release as of 10.12.2024). This is as reported by Microsoft Defender.

@ne-bbahn
Copy link
Contributor

Thank you for raising these to our attention. Python 3.12.8 released one week ago today. As this was quite recently, many of the critical libraries that we need for NCPA to function have not yet been updated to support 3.12.8. I will continue to check until they are functional and will add the update to the next release as soon as possible.

@ne-bbahn
Copy link
Contributor

The Windows version is now using Python 3.12.8, but as the Linux versions are not yet compatible with Python 3.12, I will leave this open for now.

@barww
Copy link
Author

barww commented Jan 23, 2025

Thanks for update.

@barww
Copy link
Author

barww commented Jan 27, 2025

FYI. Unfortunately these CVEs (CVE-2024-12254, CVE-2024-9287) are still present and it is now reported that Python versions 3.12.0 (including) up to 3.14.0a2 (excluding) are vulnerable. I understand v3.14 is currently pre-release as of 27-Jan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants