CVE-2024-28102
MEDIUM6.8EPSS 0.38%python-jwcrypto - security update
發布日:2024/3/6修改日:2026/4/28
描述
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.
受影響套件(3)
- Debian/python-jwcryptofrom 0, < 0.8.0-1+deb11u1
- Debian/python-jwcryptofrom 0, < 0.8.0-1+deb11u1
- PyPI/jwcryptofrom 0, < 1.5.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-28102
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2024-28102
- PATCHhttps://github.com/latchset/jwcrypto
- WEBhttps://github.com/latchset/jwcrypto/commit/90477a3b6e73da69740e00b8161f53fea19b831f
- WEBhttps://github.com/latchset/jwcrypto/security/advisories/GHSA-j857-7rvv-vj97
- WEBhttps://lists.debian.org/debian-lts-announce/2024/09/msg00026.html
- WEBhttps://www.vicarius.io/vsociety/posts/denial-of-service-vulnerability-discovered-in-jwcrypto-cve-2024-28102-28103