[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-33664Date: (C)2024-04-26   (M)2024-04-29


python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

Reference:
https://github.com/mpdavis/python-jose/issues/344
https://github.com/mpdavis/python-jose/pull/345

© SecPod Technologies