UbuntuUpdates.org

Package "python3-jwt"

Name: python3-jwt

Description:

Python 3 implementation of JSON Web Token

Latest version: 1.5.3+ds1-1ubuntu0.1
Release: bionic (18.04)
Level: updates
Repository: main
Head package: pyjwt
Homepage: https://github.com/jpadilla/pyjwt

Links


Download "python3-jwt"


Other versions of "python3-jwt" in Bionic

Repository Area Version
base main 1.5.3+ds1-1
security main 1.5.3+ds1-1ubuntu0.1

Changelog

Version: 1.5.3+ds1-1ubuntu0.1 2022-07-20 04:07:12 UTC

  pyjwt (1.5.3+ds1-1ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Signing key confusion via public key signature
    - debian/patches/CVE-2022-29217.patch: update jwt/algorithms.py to
      disallow using SSH keys as a HMAC secret.
    - CVE-2022-29217

 -- Alex Murray <email address hidden> Tue, 19 Jul 2022 15:53:32 +0930

CVE-2022-29217 PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT toke



About   -   Send Feedback to @ubuntu_updates