Vulnerabilities
Vulnerable Software
python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
CVSS Score
6.5
EPSS Score
0.007
Published
2024-04-26
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-04-26


Contact Us

Shodan ® - All rights reserved