Resource Consumption Affecting python-jose package, versions [0,]
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PYTHONJOSE-6674054
- published 26 Apr 2024
- disclosed 26 Apr 2024
- credit P3ngu1nW
Introduced: 26 Apr 2024
CVE-2024-33664 Open this link in a new tabHow to fix?
There is no fixed version for python-jose
.
Overview
Affected versions of this package are vulnerable to Resource Consumption due to the decoding process of a crafted JSON Web Encryption (JWE) token with a high compression ratio. This vulnerability is akin to a "JWT bomb" scenario, where the system's resources can be overwhelmed.
References
CVSS Scores
version 3.1