<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">See picture below:<br />
<img src="/assets/uploads/files/1617559284931-91cb8e55-5b68-46f8-b108-8bc0a605de2c-image-resized.png" alt="91cb8e55-5b68-46f8-b108-8bc0a605de2c-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Regards.</p>
]]></description><link>https://vulndetect.org/topic/1063/solved-yubikey-manager-not-displayed-as-insecure-with-an-embedded-insecure-python-and-lower-version-recommended</link><generator>RSS for Node</generator><lastBuildDate>Mon, 11 May 2026 11:56:00 GMT</lastBuildDate><atom:link href="https://vulndetect.org/topic/1063.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 04 Apr 2021 18:01:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended on Thu, 08 Apr 2021 10:41:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gregalexandre" aria-label="Profile: gregalexandre">@<bdi>gregalexandre</bdi></a> OK, then I mark this issue as <strong>solved</strong>.</p>
]]></description><link>https://vulndetect.org/post/4268</link><guid isPermaLink="true">https://vulndetect.org/post/4268</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Thu, 08 Apr 2021 10:41:53 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended on Tue, 06 Apr 2021 19:18:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: olli_s">@<bdi>olli_s</bdi></a> : you can close as lower version of Yubikey is no more recommended.</p>
]]></description><link>https://vulndetect.org/post/4266</link><guid isPermaLink="true">https://vulndetect.org/post/4266</guid><dc:creator><![CDATA[GregAlexandre]]></dc:creator><pubDate>Tue, 06 Apr 2021 19:18:12 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended on Mon, 05 Apr 2021 11:14:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gregalexandre" aria-label="Profile: gregalexandre">@<bdi>gregalexandre</bdi></a> Tell me, if this can be closed. Thank you!</p>
]]></description><link>https://vulndetect.org/post/4265</link><guid isPermaLink="true">https://vulndetect.org/post/4265</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Mon, 05 Apr 2021 11:14:36 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended on Sun, 04 Apr 2021 19:19:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: tom">@<bdi>tom</bdi></a> :<br />
Yubikey manager may not be affected by the vulnerability of Python. But it may allow wrong usage of the version of Python they install.</p>
<p dir="auto">Yes, the problem is the same with java, where you can have multiple unsafe versions of java installed and not updated by multiple products.</p>
<p dir="auto">During an attack, the attacker may choose to use the vulnerable (embedded) product to run malicious actions (eg; the one that allow it to increase it rights).</p>
<p dir="auto">I do not look at the python vulnerability. It may be acceptable. But this not coherent with defense-in-depth.</p>
<p dir="auto">I understand your point of view even if I cannot agree.</p>
<p dir="auto">Regards.</p>
]]></description><link>https://vulndetect.org/post/4255</link><guid isPermaLink="true">https://vulndetect.org/post/4255</guid><dc:creator><![CDATA[GregAlexandre]]></dc:creator><pubDate>Sun, 04 Apr 2021 19:19:43 GMT</pubDate></item><item><title><![CDATA[Reply to [Solved] Yubikey manager: not displayed as insecure with an embedded insecure python and lower version recommended on Sun, 04 Apr 2021 18:27:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gregalexandre" aria-label="Profile: gregalexandre">@<bdi>gregalexandre</bdi></a> I don't know how Python is utilized by Yubikey Manager, so it is hard to assess if it is affected by the vulnerability in Python.</p>
<p dir="auto">Unless Yubikey (or some independent researcher) makes any statements that indicate Yubikey Manager to be affected, then we will not flag it as being affected.</p>
<p dir="auto">For some "libraries" it is dead obvious whether the "parent" product is affected (or not) by a vulnerability, but in a case like this, it is dependent upon their specific implementation of Python (and I have no knowledge about how they use it). The same goes for many applications that utilize Java.</p>
<p dir="auto">Given the latest vuln that was fixed in Python, I wouldn't worry much though.</p>
]]></description><link>https://vulndetect.org/post/4254</link><guid isPermaLink="true">https://vulndetect.org/post/4254</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Sun, 04 Apr 2021 18:27:25 GMT</pubDate></item></channel></rss>