CVE-2024-33664
Publication date 26 April 2024
Last updated 24 July 2024
Ubuntu priority
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-jose | 24.10 oracular | Not in release |
24.04 LTS noble |
Needs evaluation
|
|
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal | Not in release |