CVE-2024-33664

Publication date 26 April 2024

Last updated 24 July 2024


Ubuntu priority

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a “JWT bomb.” This is similar to CVE-2024-21319.

Status

Package Ubuntu Release Status
python-jose 25.04 plucky Not in release
24.10 oracular Not in release
24.04 LTS noble
Needs evaluation
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Needs evaluation
20.04 LTS focal Not in release