Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202403-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: UltraJSON: Multiple Vulnerabilities Date: March 03, 2024 Bugs: #855689 ID: 202403-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting. Background ========== UltraJSON is an ultra fast JSON encoder and decoder written in pure C with bindings for Python 3.8+. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ dev-python/ujson < 5.4.0 > = 5.4.0 Description =========== Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this allowed for potential key confusion and value overwriting in dictionaries. All users parsing JSON from untrusted sources are vulnerable. From version 5.4.0, UltraJSON decodes lone surrogates in the same way as the standard library's `json` module does, preserving them in the parsed output. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All UltraJSON users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/ujson-5.4.0" References ========== [ 1 ] CVE-2022-31116 https://nvd.nist.gov/vuln/detail/CVE-2022-31116 [ 2 ] CVE-2022-31117 https://nvd.nist.gov/vuln/detail/CVE-2022-31117 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202403-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3545-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise Module for Public Cloud 15 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server for SAP Applications 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key formats (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 15: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-2022-3545=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 15 (noarch): python3-PyJWT-1.5.3-150000.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE Security Fix for python-PyJWT tackles essential oversight flaws tagged as high priority. Stay updated!. SUSE Linux Security, Python Security Update, Key Confusion Fix, Software Patch, Python-PyJWT Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2401-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Public Cloud 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2022-2401=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-PyJWT-1.5.3-3.16.1 python3-PyJWT-1.5.3-3.16.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE Security Update for python-PyJWT rectifies significant key ambiguity flaw, providing crucial patch guidelines.. SUSE Python PyJWT Update KeyConfusion. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2402-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager RetailBranch Server 4.3 SUSE Manager Server 4.1 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2402=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2402=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-2402=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-2402=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-2402=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-2402=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-2402=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-2402=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-2402=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-2402=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP3-2022-2402=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-2402=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-2402=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-2402=1 Package List: - openSUSE Leap 15.4 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - openSUSE Leap 15.3 (noarch): python2-PyJWT-1.7.1-150200.3.3.1 python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Server 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Retail Branch Server 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Proxy 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server 15-SP2-BCL (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (noarch): python2-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Enterprise Storage 7 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE has issued a significant patch for python-PyJWT addressing a critical key ambiguity vulnerability. Discover furtherdetails about the update.. SUSE Update, Security Fix, Python-PyJWT, Linux Security. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2403-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise Module for Public Cloud 15-SP1 SUSE Linux Enterprise Module for Public Cloud 15-SP2 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP2 SUSE Linux Enterprise Storage 6 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.0 SUSE Manager Proxy 4.1 SUSE Manager Retail Branch Server 4.0 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.0 SUSE Manager Server 4.1 ______________________________________________________________________________ An update thatfixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2403=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2403=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2403=1 - SUSE Linux Enterprise Module for Public Cloud 15-SP2: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2022-2403=1 - SUSE Linux Enterprise Module for Public Cloud 15-SP1: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP1-2022-2403=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2403=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2403=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2403=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Module for Public Cloud 15-SP2(noarch): python2-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Module for Public Cloud 15-SP1 (noarch): python2-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Enterprise Storage 6 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE CaaS Platform 4.0 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . The latest python-PyJWT update addresses significant vulnerabilities and enhances security protocols within SUSE environments, offering detailed patch instructions for system administrators.. SUSE Python Security, Key Confusion, python-PyJWT Advisory, Security Updates, SUSE Patch Instructions. . Severity: Important. LinuxSecurity.com Team
Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-4ae9110f51 2022-06-01 01:25:20.629814 --------------------------------------------------------------------------------Name : python-jwt Product : Fedora 35 Version : 2.4.0 Release : 1.fc35 URL : https://github.com/jpadilla/pyjwt Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. --------------------------------------------------------------------------------Update Information: Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24 --------------------------------------------------------------------------------ChangeLog: * Thu May 19 2022 Major Hayden - 2.4.0-1 - Update to 2.4.0 (#2085157) - Fix CVE-2022-29217 (#2088546) * Tue Apr 26 2022 Carl George - 2.3.0-3 - Convert to pyproject macros * Fri Jan 21 2022 Fedora Release Engineering - 2.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Tue Oct 26 2021 Joel Capitao - 2.3.0-1 - Update to 2.3.0 (rhbz#2011642) * Sun Oct 3 2021 Kevin Fenzi - 2.1.0-3 - Relax python-cryptography requirements ( rhbz#2010061 ) --------------------------------------------------------------------------------References: [ 1 ] Bug #2085157 - python-jwt-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2085157 [ 2 ] Bug #2088546 - CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088546 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-4ae9110f51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3cf456dc20 2022-05-27 01:08:53.900461 --------------------------------------------------------------------------------Name : python-jwt Product : Fedora 36 Version : 2.4.0 Release : 1.fc36 URL : https://github.com/jpadilla/pyjwt Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. --------------------------------------------------------------------------------Update Information: Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24 --------------------------------------------------------------------------------ChangeLog: * Thu May 19 2022 Major Hayden - 2.4.0-1 - Update to 2.4.0 (#2085157) - Fix CVE-2022-29217 (#2088546) * Tue Apr 26 2022 Carl George - 2.3.0-3 - Convert to pyproject macros --------------------------------------------------------------------------------References: [ 1 ] Bug #2085157 - python-jwt-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2085157 [ 2 ] Bug #2088546 - CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088546 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3cf456dc20' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.