-
Notifications
You must be signed in to change notification settings - Fork 56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SECURITY] Version 1.2.4 is effected by CVE-2024-23342 in edcsa #44
Comments
Hey @kartikye, we're on it and are exploring a different cryptographic backend or a new package altogether. Keep an eye out for updates. |
edcsa is being brought in by python-jose, which has not had a release since 2021. Most of the Python ecosystem seems to have moved to pyjwt. |
1.2.5 is also affected :( |
Any updates on this. python-jose is now failing pip audits for these two: |
Any update on this matter? this CVE affects a lot of our services' score. |
Hi @kartikye, @r-thomson, @geekkun, @3point14guy, @Natim @yahel2410 - v1.2.6 solves this by moving to |
https://nvd.nist.gov/vuln/detail/CVE-2024-23342
The text was updated successfully, but these errors were encountered: