Insecure encryption algorithm In python-jose
Description
python-jose algorithm confusion with OpenSSH ECDSA keys python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | - | ||
pypi | 3.4.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.