Debian Python-Jose vulnerabilities
4 known vulnerabilities affecting debian/python-jose.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-33663HIGHCVSS 7.42024
CVE-2024-33663 [HIGH] CVE-2024-33663: python-jose - python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and ot...
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Scope: local
bookworm: open
debian
CVE-2024-33664MEDIUMCVSS 6.82024
CVE-2024-33664 [MEDIUM] CVE-2024-33664: python-jose - python-jose through 3.3.0 allows attackers to cause a denial of service (resourc...
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Scope: local
bookworm: open
debian
CVE-2024-29370MEDIUMCVSS 5.32024
CVE-2024-29370 [MEDIUM] CVE-2024-29370: python-jose - In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attac...
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
S
debian
CVE-2016-7036LOWCVSS 9.82016
CVE-2016-7036 [CRITICAL] CVE-2016-7036: python-jose - python-jose before 1.3.2 allows attackers to have unspecified impact by leveragi...
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
Scope: local
bookworm: resolved
debian