NA

CVE-2024-33663

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

python-jose up to and including 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

Vendor Advisories

Debian Bug report logs - #1070375 python-jose: CVE-2024-33663 CVE-2024-33664 Package: src:python-jose; Maintainer for src:python-jose is Debian Python Team <team+python@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 4 May 2024 16:03:01 UTC Severity: important Tags: security, upstrea ...