Описание
Security update for python-Authlib
This update for python-Authlib fixes the following issues:
- Update to version 1.3.1
- CVE-2024-37568: Fixed algorithm confusion with asymmetric public keys. (bsc#1226138)
Список пакетов
SUSE Linux Enterprise Module for Python 3 15 SP6
python311-Authlib-1.3.1-150600.3.3.1
openSUSE Leap 15.6
python311-Authlib-1.3.1-150600.3.3.1
Ссылки
- Link for SUSE-SU-2024:2064-1
- E-Mail link for SUSE-SU-2024:2064-1
- SUSE Security Ratings
- SUSE Bug 1226138
- SUSE CVE CVE-2024-37568 page
Описание
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP6:python311-Authlib-1.3.1-150600.3.3.1
openSUSE Leap 15.6:python311-Authlib-1.3.1-150600.3.3.1
Ссылки
- CVE-2024-37568
- SUSE Bug 1226138