Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-37568
Description:lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Test IDs: 1.3.6.1.4.1.25623.1.0.887251   1.3.6.1.4.1.25623.1.0.887245   1.3.6.1.4.1.25623.1.1.10.2024.0238   1.3.6.1.4.1.25623.1.0.856238  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-37568
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FHJI32SN4FNAUVNALVGOKWHNSQ6XS3M5/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IZI7HYGN7VZAYFV6UV3SRLYF7QGERXIU/
https://github.com/lepture/authlib/issues/654




© 1998-2025 E-Soft Inc. All rights reserved.