Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-45768

Опубликовано: 31 июл. 2025
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pyjwt_project:pyjwt:2.10.1:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.0016
Низкий

7 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 года назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

msrc
11 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 7
debian
около 1 года назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is ...

CVSS3: 7
github
около 1 года назад

pyjwt v2.10.1 was discovered to contain weak encryption.

EPSS

Процентиль: 6%
0.0016
Низкий

7 High

CVSS3

Дефекты

CWE-311