Описание
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-apps/jammy | needs-triage | |
esm-apps/noble | needs-triage | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | needs-triage | |
mantic | ignored | end of life, was needs-triage |
noble | needs-triage | |
oracular | DNE | |
plucky | DNE |
Показывать по
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
python-jose through 3.3.0 allows attackers to cause a denial of servic ...
python-jose denial of service via compressed JWE content
EPSS
5.3 Medium
CVSS3