Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

algorithm confusion issue #367

Open
prasadayush opened this issue Jan 30, 2025 · 1 comment
Open

algorithm confusion issue #367

prasadayush opened this issue Jan 30, 2025 · 1 comment

Comments

@prasadayush
Copy link

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

Below are the risk factors associated to this issue -
Critical severity, Package in use

Vulnerability link - https://nvd.nist.gov/vuln/detail/CVE-2024-33663

@KishinNext
Copy link

I recommend updating to the latest version of python-jose, as this vulnerability was addressed in issue #346 and fixed in #369.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants