Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjwg-qfpm-7377

Опубликовано: 26 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

python-jose denial of service via compressed JWE content

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

Пакеты

Наименование

python-jose

pip
Затронутые версииВерсия исправления

< 3.4.0

3.4.0

EPSS

Процентиль: 9%
0.00035
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

redhat
около 1 года назад

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

CVSS3: 5.3
nvd
около 1 года назад

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

CVSS3: 5.3
debian
около 1 года назад

python-jose through 3.3.0 allows attackers to cause a denial of servic ...

suse-cvrf
около 1 года назад

Security update for python-python-jose

EPSS

Процентиль: 9%
0.00035
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400