Bug 1221230 (CVE-2024-28102) - VUL-0: CVE-2024-28102: python-jwcrypto: malicious JWE token can cause denial of service
Summary: VUL-0: CVE-2024-28102: python-jwcrypto: malicious JWE token can cause denial ...
Status: RESOLVED FIXED
Alias: CVE-2024-28102
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Giacomo Leidi
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/396790/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-28102:6.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-11 10:00 UTC by SMASH SMASH
Modified: 2024-06-11 12:17 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-03-11 10:00:39 UTC
JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in a malicious JWE Token with a high compression ratio. When the server processes this token, it will consume a lot of memory and processing time. Version 1.5.6 fixes this vulnerability by limiting the maximum token length.


References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28102
https://bugzilla.redhat.com/show_bug.cgi?id=2268758
Comment 4 OBSbugzilla Bot 2024-03-25 13:35:02 UTC
This is an autogenerated message for OBS integration:
This bug (1221230) was mentioned in
https://build.opensuse.org/request/show/1161389 Factory / python-jwcrypto
Comment 5 Giacomo Leidi 2024-06-11 12:17:48 UTC
https://build.suse.de/request/show/324748 has been integrated