CVE-2024-33663

Aliases:GHSA-6c5p-j8vq-pqhjPYSEC-2024-232ECHO-04e0-8ccc-e285
Analyzed
Published: 25 Apr 2024, 00:00
Last modified:03 Sept 2024, 19:34

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.92% LOW
1% probability +0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

25 Apr 2024, 00:00
Published
Vulnerability first disclosed
03 Sept 2024, 19:34
Last Modified
Vulnerability information updated

Description

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

CVSS Metrics

  • v4.0CRITICALScore: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.92% Percentile: 76%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • PyPIpython-jose

    < 3.4.0

  • python-jose_projectpython-jose

    ≤ 3.3.0

References (5)