python-jose 在 3.5.0 及之前版本中,在 HMAC 初始化过程中未能正确验证非对称密钥,会接受缺少 PEM 头尾(armor)或 SSH 前缀的 DER 编码公钥。如果未显式限制算法,持有服务公钥的攻击者可以伪造能通过验证的 HS256 令牌。此问题是对 CVE-2024-33663 的不完整修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mpdavis | python-jose | ≤ 3.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mpdavis | python-jose | 0 ~ 3.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet