ZeroHour

CVE-2024-33664

PoC ×2
CVSS 3.1
5.3 medium
EPSS
<1%p54
Published
()
Modified
Description

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

Vendors
python-jose project
Products
python-jose
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.