VUL-0: CVE-2024-33663: python-python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats
VUL-0: CVE-2024-33664: python-python-jose: denial of service via decoding of a JSON Web Encryption (JWE ) token with a high compression ratio
dgarcia
important
security
Security update for python-python-jose
This update for python-python-jose fixes the following issues:
- CVE-2024-33664: Fixed denial of service via decoding of a JSON Web Encryption (bsc#1223422)
- CVE-2024-33663: Fixed algorithm confusion with OpenSSH ECDSA keys (bsc#1223417)
python-python-jose