Description
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages6 packages
🔴Vulnerability Details
6OSVCVE-2024-37568: lepture Authlib before 1↗2024-06-09 ▶ OSVAuthlib has algorithm confusion with asymmetric public keys↗2024-06-09 ▶ GHSAAuthlib has algorithm confusion with asymmetric public keys↗2024-06-09 ▶ OSVCVE-2024-33663: python-jose through 3↗2024-04-26 ▶ OSVpython-jose algorithm confusion with OpenSSH ECDSA keys↗2024-04-26 ▶ 📋Vendor Advisories
3Red Hatpython-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats↗2024-04-26 ▶ DebianCVE-2024-33663: python-jose - python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and ot...↗2024 ▶ DebianCVE-2024-37568: python-authlib - lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys...↗2024 ▶