NA

CVE-2024-33664

Published: 26/04/2024 Updated: 26/04/2024

Vulnerability Summary

python-jose up to and including 3.3.0 allows malicious users to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

Vendor Advisories

Debian Bug report logs - #1070375 python-jose: CVE-2024-33663 CVE-2024-33664 Package: src:python-jose; Maintainer for src:python-jose is Debian Python Team <team+python@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 4 May 2024 16:03:01 UTC Severity: important Tags: security, upstrea ...