Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2064-1

Опубликовано: 18 июн. 2024
Источник: suse-cvrf

Описание

Security update for python-Authlib

This update for python-Authlib fixes the following issues:

  • Update to version 1.3.1
  • CVE-2024-37568: Fixed algorithm confusion with asymmetric public keys. (bsc#1226138)

Список пакетов

SUSE Linux Enterprise Module for Python 3 15 SP6
python311-Authlib-1.3.1-150600.3.3.1
openSUSE Leap 15.6
python311-Authlib-1.3.1-150600.3.3.1

Описание

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)


Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP6:python311-Authlib-1.3.1-150600.3.3.1
openSUSE Leap 15.6:python311-Authlib-1.3.1-150600.3.3.1

Ссылки