chdsbd / kodiak

🔮 A bot to automatically update and merge GitHub PRs

Home Page:https://kodiakhq.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2020-36242 and CVE-2020-25659

StephenRadachy opened this issue · comments

I don't think Kodiak is vulnerable to this issue because Kodiak doesn't symmetrically encrypt multi-GB values.

Regarding the timing attacks, I don't think that's an issue for us because we don't allow users to initiate connections to Kodiak, only GitHub

But like these other vulnerabilities, I'd welcome a PR to update the package.

We've upgraded to cryptography 3.4.6 with #826, so this issue is no longer valid