critical
Security update for python-pyjwt
SUSE-SLE-Module-Basesystem-15-SP4-2023-794
This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed Key confusion through non-blocklisted public key formats (bsc#1199756). - Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629) - Update to 2.4.0 (bsc#1199756) - Explicit check the key for ECAlgorithm - Don't use implicit optionals - documentation fix: show correct scope - fix: Update copyright information - Don't mutate options dictionary in .decode_complete() - Add support for Python 3.10 - api_jwk: Add PyJWKSet.__getitem__ - Update usage.rst - Docs: mention performance reasons for reusing RSAPrivateKey when encoding - Fixed typo in usage.rst - Add detached payload support for JWS encoding and decoding - Replace various string interpolations with f-strings by
-
Release DateMar 17 2023
-
References
-
Typesecurity
-
Severitycritical
cloud_download Downloads
Basesystem Module 15.4 x86_64
-
Packagespython-PyJWT
JSON Web Token implementation in Pythonpython3-PyJWT2.4.0-150200.3.6.2 lock src
JSON Web Token implementation in Python2.4.0-150200.3.6.2 lock rpm
Basesystem Module 15.4 s390x
-
Packagespython-PyJWT
JSON Web Token implementation in Pythonpython3-PyJWT2.4.0-150200.3.6.2 lock src
JSON Web Token implementation in Python2.4.0-150200.3.6.2 lock rpm
Basesystem Module 15.4 ppc64le
-
Packagespython-PyJWT
JSON Web Token implementation in Pythonpython3-PyJWT2.4.0-150200.3.6.2 lock src
JSON Web Token implementation in Python2.4.0-150200.3.6.2 lock rpm
Basesystem Module 15.4 aarch64
-
Packagespython-PyJWT
JSON Web Token implementation in Pythonpython3-PyJWT2.4.0-150200.3.6.2 lock src
JSON Web Token implementation in Python2.4.0-150200.3.6.2 lock rpm