Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Version 1.2.4 is effected by CVE-2024-23342 in edcsa #44

Closed
kartikye opened this issue Feb 13, 2024 · 7 comments
Closed

[SECURITY] Version 1.2.4 is effected by CVE-2024-23342 in edcsa #44

kartikye opened this issue Feb 13, 2024 · 7 comments

Comments

@kartikye
Copy link

https://nvd.nist.gov/vuln/detail/CVE-2024-23342

@robert-mings
Copy link
Collaborator

Hey @kartikye, we're on it and are exploring a different cryptographic backend or a new package altogether.

Keep an eye out for updates.

@r-thomson
Copy link

edcsa is being brought in by python-jose, which has not had a release since 2021. Most of the Python ecosystem seems to have moved to pyjwt.

@geekkun
Copy link

geekkun commented Mar 1, 2024

1.2.5 is also affected :(

@3point14guy
Copy link

Any updates on this. python-jose is now failing pip audits for these two:
https://github.com/advisories?query=GHSA-6c5p-j8vq-pqhj
https://github.com/advisories?query=GHSA-cjwg-qfpm-7377

@Natim
Copy link
Contributor

Natim commented May 28, 2024

We now have two alternates #48 and #49

@yahel2410
Copy link

Any update on this matter? this CVE affects a lot of our services' score.

@robert-mings
Copy link
Collaborator

Hi @kartikye, @r-thomson, @geekkun, @3point14guy, @Natim @yahel2410 - v1.2.6 solves this by moving to pyjwt and is now available. Please update as soon as possible. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants