CVE-2024-33664 – python-jose through 3.3.0 allows attackers to cause a denial of service (resource …

Vuln ID: CVE-2024-33664

Published:  2024-04-26  00:15:09.060

Description: python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a “JWT bomb.” This is similar to CVE-2024-21319.

Base Score:

Vector:

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):