Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-45768

Опубликовано: 31 июл. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7

Описание

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

РелизСтатусПримечание
devel

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

esm-infra/xenial

not-affected

jammy

not-affected

noble

not-affected

plucky

not-affected

questing

not-affected

upstream

needs-triage

Показывать по

7 High

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
6 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 7
nvd
6 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

msrc
5 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

CVSS3: 7
debian
6 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is ...

CVSS3: 7
github
6 месяцев назад

pyjwt v2.10.1 was discovered to contain weak encryption.

7 High

CVSS3