Hi,

You are receiving an AlmaLinux Security update email because you subscribed to 
receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Moderate
Release date: 2024-05-07

Summary:

The python-jwcrypto package provides Python implementations of the JSON Web Key 
(JWK), JSON Web Signature (JWS), JSON Web Encryption (JWE), and JSON Web Token 
(JWT) JOSE (JSON Object Signing and Encryption) standards.

Security Fix(es):

* python-jwcrypto: malicious JWE token can cause denial of service 
(CVE-2024-28102)

For more details about the security issue(s), including the impact, a CVSS 
score, acknowledgments, and other related information, refer to the CVE page(s) 
listed in the References section.

Full details, updated packages, references, and other related information: 
https://errata.almalinux.org/9/ALSA-2024-2559.html

This message is automatically generated, please don’t reply. For further 
questions, please, contact us via the AlmaLinux community chat: 
https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on 
https://lists.almalinux.org.

Kind regards,
AlmaLinux Team

Reply via email to