RHSA-2024:2559: Moderate: python-jwcrypto security update
Moderate: python-jwcrypto security update
Other sources
The python-jwcrypto package provides Python implementations of the JSON Web Key (JWK), JSON Web Signature (JWS), JSON Web Encryption (JWE), and JSON Web Token (JWT) JOSE (JSON Object Signing and Encryption) standards.Security Fix(es): python-jwcrypto: malicious JWE token can cause denial of service (CVE-2024-28102) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2559?
The severity of RHSA-2024:2559 is classified as moderate.
How do I fix RHSA-2024:2559?
You can fix RHSA-2024:2559 by updating to the patched version of the python-jwcrypto package, specifically version 0.8-5.el9_4.
Which packages are affected by RHSA-2024:2559?
The affected packages for RHSA-2024:2559 include python-jwcrypto and python3-jwcrypto up to version 0.8-5.el9_4.
What specific vulnerabilities are addressed in RHSA-2024:2559?
RHSA-2024:2559 addresses security issues in the python-jwcrypto package related to JSON Web Key and token standards.
Which Red Hat Enterprise Linux products are impacted by RHSA-2024:2559?
RHSA-2024:2559 impacts several Red Hat Enterprise Linux products including the x86_64 and ARM architectures.