Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-33664

Description

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

POC

Reference

- https://github.com/mpdavis/python-jose/issues/344

- https://www.vicarius.io/vsociety/posts/jwt-bomb-in-python-jose-cve-2024-33664

Github

- https://github.com/BuloZB/BuloCloudSentinel

- https://github.com/blemis/anscomm

- https://github.com/iotdscreator/iotdscreator-dataset