Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-33663

Description

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

POC

Reference

- https://github.com/mpdavis/python-jose/issues/346

- https://www.vicarius.io/vsociety/posts/algorithm-confusion-in-python-jose-cve-2024-33663

Github

- https://github.com/BuloZB/BuloCloudSentinel

- https://github.com/HasnainKousar/is601_module14

- https://github.com/blemis/anscomm