python-jose
python-jose copied to clipboard
CVE-2024-23342, High level vulnerability
Hey guys, python-jose is affected by CVE-2024-23342 through its ecdsa dependency. The vulnerability stems from insufficient validation in ECDSA key handling, which could potentially allow signature forgery. Could you please take a look and see if there’s a way to address this?
Is there anything regarding this issue?