Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
python-jose 安全漏洞
Vulnerability Description
python-jose是Michael Davis个人开发者的一个 Python 中的 JOSE 实现。 python-jose 3.3.0及之前版本存在安全漏洞,该漏洞源于允许攻击者在解码过程中通过特制的高压缩率 JSON Web 加密 (JWE) 令牌造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A