CVE-2024-33664
published 2024-04-26CVE-2024-33664: python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token…
PriorityP423medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.78%
52.0th percentile
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-jose | — | — |
| python-jose_project | python-jose | <= 3.3.0 | — |
| python-jose_project | python-jose | >= 0 < 3.4.0 | 3.4.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ghsa6.8MEDIUM
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-jose: allows attackers to cause a denial of service
vendor_redhat·2024-04-26·CVSS 6.8
CVE-2024-33664 [MEDIUM] python-jose: allows attackers to cause a denial of service
python-jose: allows attackers to cause a denial of service
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Package: automation-controller (Red Hat Ansible Automation Platform 2) - Not affected
Package: python-jose (Red Hat Ansible Automation Platform 2) - Not affected
Debian
CVE-2024-33664: python-jose - python-jose through 3.3.0 allows attackers to cause a denial of service (resourc...
vendor_debian·2024·CVSS 6.8
CVE-2024-33664 [MEDIUM] CVE-2024-33664: python-jose - python-jose through 3.3.0 allows attackers to cause a denial of service (resourc...
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Scope: local
bookworm: open
OSV
python-jose denial of service via compressed JWE content
osv·2024-04-26·CVSS 6.8
CVE-2024-33664 [MEDIUM] python-jose denial of service via compressed JWE content
python-jose denial of service via compressed JWE content
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
GHSA
python-jose denial of service via compressed JWE content
ghsa·2024-04-26·CVSS 6.8
CVE-2024-33664 [MEDIUM] CWE-400 python-jose denial of service via compressed JWE content
python-jose denial of service via compressed JWE content
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
OSV
CVE-2024-33664: python-jose through 3
osv·2024-04-26·CVSS 6.8
CVE-2024-33664 [MEDIUM] CVE-2024-33664: python-jose through 3
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
No detection rules found.
No public exploits indexed.
https://github.com/mpdavis/python-jose/issues/344https://github.com/mpdavis/python-jose/pull/345https://www.vicarius.io/vsociety/posts/jwt-bomb-in-python-jose-cve-2024-33664https://github.com/mpdavis/python-jose/issues/344https://github.com/mpdavis/python-jose/pull/345https://www.vicarius.io/vsociety/posts/jwt-bomb-in-python-jose-cve-2024-33664
2024-04-26
Published