CVE-2024-29370
MEDIUMDescription
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| python-jose_project | python-jose |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-29370? +
How severe is CVE-2024-29370? +
What products are affected by CVE-2024-29370? +
How do I check if I'm vulnerable to CVE-2024-29370? +
Related Vulnerabilities
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory …
pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can …
.NET and Visual Studio Denial of Service Vulnerability
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can …
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In …
The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted …