Skip to content

CVE-2017-11424 Applies to python-jose as well! #62

@sirosen

Description

@sirosen

CVE-2017-11424 details a key confusion attack against pyjwt.

As I understand it, we just need to add another magic string to this check

Not being a crypto expert, I'll open a pull request with the fix described in the CVE, but would appreciate someone else taking a look at the CVE before merging.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions