Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-45768

Опубликовано: 31 июл. 2025
Источник: debian

Описание

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pyjwtunfixedpackage

Примечания

  • disputed upstream, negligible security impact, cf.

  • https://github.com/jpadilla/pyjwt/issues/1080#issuecomment-3164212492

  • https://github.com/advisories/GHSA-xpf8-484v-j9w6

  • https://github.com/jpadilla/pyjwt/security/advisories/GHSA-72ff-rqxp-4hrh

Связанные уязвимости

CVSS3: 7
ubuntu
3 месяца назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 5.6
redhat
3 месяца назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 7
nvd
3 месяца назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

msrc
2 месяца назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 7
github
3 месяца назад

pyjwt v2.10.1 was discovered to contain weak encryption.