Bug 2088544 (CVE-2022-29217)
| Summary: | CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Nobody <nobody> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | adudiak, alex, ali.erdinc.koroglu, aoconnor, bbuckingham, bcoca, bcourt, bdettelb, bniver, chousekn, cluster-maint, cmeyers, dmendiza, eglynn, ehelms, fedora, flucifre, gmeno, i, infra-sig, jcammara, jhardy, jjoyce, jobarker, jperrin, jpopelka, jschluet, jsherril, jwong, kaycoth, kevin, kshier, lbragsta, lhh, lzap, mabashia, mbenjamin, mburns, mhackett, mhulan, msuchy, nkinder, nmoumoul, notting, oalbrigt, oblaut, oliver, orabin, pcreech, python-sig, rbean, rchan, rhos-maint, rominf, rpetrell, sdoran, slavek.kabrda, slinaber, smcdonal, sostapov, spotrh, spower, stcannon, suraia, tfister, thalman, tvignaud, vereddy, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A vulnerability was found in python-jwt. This issue happens when PyJWT supports multiple different JWT signing algorithms. This flaw allows an attacker submitting the JWT token to choose the used signing algorithm, leading to key confusion through non-blocklisted public key formats.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2089226, 2089227, 2089229, 2088546, 2088547, 2088548, 2088549, 2088550, 2088551, 2088552, 2088553, 2088554, 2088555, 2088556, 2088557, 2089144, 2089145, 2089146, 2089147, 2089149, 2089230, 2089231, 2095893, 2095894, 2095895, 2095896, 2095897, 2098090, 2098091, 2098092, 2207679, 2258843 | ||
| Bug Blocks: | 2088545 | ||
|
Description
Guilherme de Almeida Suckevicz
2022-05-19 16:44:21 UTC
Created cascadia-code-fonts tracking bugs for this issue: Affects: fedora-all [bug 2088547] Created jetbrains-mono-fonts tracking bugs for this issue: Affects: fedora-all [bug 2088548] Created openstack-keystone tracking bugs for this issue: Affects: openstack-rdo [bug 2088555] Created openstack-mistral tracking bugs for this issue: Affects: openstack-rdo [bug 2088556] Created openstack-vitrage tracking bugs for this issue: Affects: openstack-rdo [bug 2088557] Created picard tracking bugs for this issue: Affects: fedora-all [bug 2088549] Created python-PyGithub tracking bugs for this issue: Affects: fedora-all [bug 2088550] Created python-adal tracking bugs for this issue: Affects: fedora-all [bug 2088551] Created python-ibm-cloud-sdk-core tracking bugs for this issue: Affects: fedora-all [bug 2088552] Created python-jwt tracking bugs for this issue: Affects: fedora-all [bug 2088546] Created python-oauthlib tracking bugs for this issue: Affects: fedora-all [bug 2088553] Created python-twilio tracking bugs for this issue: Affects: fedora-all [bug 2088554] why was a bug filed for python-twilio for this? It seems a bug in python-jwt and python-twilio has no requires for python-jwt ? It also seems questionable that other packages listed above like "cascadia-code-fonts" were affected ? Hi, if these packages do not depend on python-jwt it's probably a false positive from our scanner tool. Running the tool again I can't even find these packages on the list anymore. Feel free to close the tracker bugs related to these packages as NOTABUG. |