UBUNTU-CVE-2017-11424
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-11424
UBUNTU-CVE-2017-11424
Summary:
Details: In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA PUBLIC KEY-----` which is not accounted for. This enables symmetric/asymmetric key confusion attacks against users using the PKCS1 PEM encoded public keys, which would allow an attacker to craft JWTs from scratch.
References: https://ubuntu.com/security/CVE-2017-11424, https://ubuntu.com/security/notices/USN-3407-1, https://www.cve.org/CVERecord?id=CVE-2017-11424
Affected packages
Package
Name: pyjwt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
