Python cryptography package version in docker image is outdated and vulnerable?

Hello,

Our security scanning tool is reporting a high severity vulnerability on the version of python cryptography bundled in the docker image (PMM version 3.9.1).

This has been open for some time and the package has not been updated in recent releases, is there a specific reason, or maybe this is a false positive?

CVE-2023-0286

Package Path: /usr/lib64/python3.9/site-packages/cryptography and /usr/lib64/python3.9/site-packages/cryptography-36.0.1-py3.9.egg-info

Current installed version: 36.0.1

Fixed version: 39.0.1

Thanks in advance,

Hi,

Thanks for letting us know. Our team is aware of it, along with the other couple of CVEs, and they are working on it.
Best.