Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
91

Gentoo: GLSA-202403-03 Normal: UltraJSON Key Confusion Threat

Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202403-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: UltraJSON: Multiple Vulnerabilities Date: March 03, 2024 Bugs: #855689 ID: 202403-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting. Background ========== UltraJSON is an ultra fast JSON encoder and decoder written in pure C with bindings for Python 3.8+. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ dev-python/ujson < 5.4.0 > = 5.4.0 Description =========== Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this allowed for potential key confusion and value overwriting in dictionaries. All users parsing JSON from untrusted sources are vulnerable. From version 5.4.0, UltraJSON decodes lone surrogates in the same way as the standard library's `json` module does, preserving them in the parsed output. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All UltraJSON users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/ujson-5.4.0" References ========== [ 1 ] CVE-2022-31116 https://nvd.nist.gov/vuln/detail/CVE-2022-31116 [ 2 ] CVE-2022-31117 https://nvd.nist.gov/vuln/detail/CVE-2022-31117 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202403-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Uncover various vulnerabilities within UltraJSON that may jeopardize Gentoo users, risking potential data loss. Prioritize safety.. Gentoo Security, UltraJSON Issues, JSON Decoder Problems, Security Advisory. . LinuxSecurity.com Team

Calendar%202 Mar 03, 2024 Gentoo
100

SUSE: 2022:3545-1 Important: python-PyJWT Key Confusion Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3545-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 15 SUSE Linux Enterprise Module for Public Cloud 15 SUSE Linux Enterprise Server 15 SUSE Linux Enterprise Server for SAP Applications 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key formats (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 15: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-2022-3545=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 15 (noarch): python3-PyJWT-1.5.3-150000.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE Security Fix for python-PyJWT tackles essential oversight flaws tagged as high priority. Stay updated!. SUSE Linux Security, Python Security Update, Key Confusion Fix, Software Patch, Python-PyJWT Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 06, 2022 Important SuSE
100

SUSE: 2023:2402-2 Urgent: python-JWT-Handler Security Token Flaw

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2401-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Module for Public Cloud 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2022-2401=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-PyJWT-1.5.3-3.16.1 python3-PyJWT-1.5.3-3.16.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE Security Update for python-PyJWT rectifies significant key ambiguity flaw, providing crucial patch guidelines.. SUSE Python PyJWT Update KeyConfusion. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2022 Important SuSE
100

SUSE: 2022:2402-1 Critical Update: Python-PyJWT Denial of Service Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2402-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager RetailBranch Server 4.3 SUSE Manager Server 4.1 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2402=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2402=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-2402=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-2402=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-2402=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-2402=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-2402=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-2402=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-2402=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-2402=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP3-2022-2402=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-2402=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-2402=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-2402=1 Package List: - openSUSE Leap 15.4 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - openSUSE Leap 15.3 (noarch): python2-PyJWT-1.7.1-150200.3.3.1 python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Server 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Retail Branch Server 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Manager Proxy 4.1 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Server 15-SP2-BCL (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (noarch): python2-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (noarch): python3-PyJWT-1.7.1-150200.3.3.1 - SUSE Enterprise Storage 7 (noarch): python3-PyJWT-1.7.1-150200.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . SUSE has issued a significant patch for python-PyJWT addressing a critical key ambiguity vulnerability. Discover furtherdetails about the update.. SUSE Update, Security Fix, Python-PyJWT, Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2022 Important SuSE
100

SUSE: 2022:2404-1 Critical: python-PyJWT Security Update

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-PyJWT ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2403-1 Rating: important References: #1199756 Cross-References: CVE-2022-29217 CVSS scores: CVE-2022-29217 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-29217 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise Module for Public Cloud 15-SP1 SUSE Linux Enterprise Module for Public Cloud 15-SP2 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP2 SUSE Linux Enterprise Storage 6 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.0 SUSE Manager Proxy 4.1 SUSE Manager Retail Branch Server 4.0 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.0 SUSE Manager Server 4.1 ______________________________________________________________________________ An update thatfixes one vulnerability is now available. Description: This update for python-PyJWT fixes the following issues: - CVE-2022-29217: Fixed key confusion through non-blocklisted public key format (bsc#1199756). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-2403=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-2403=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-2403=1 - SUSE Linux Enterprise Module for Public Cloud 15-SP2: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2022-2403=1 - SUSE Linux Enterprise Module for Public Cloud 15-SP1: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP1-2022-2403=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-2403=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-2403=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-2403=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Module for Public Cloud 15-SP2(noarch): python2-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise Module for Public Cloud 15-SP1 (noarch): python2-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE Enterprise Storage 6 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 - SUSE CaaS Platform 4.0 (noarch): python3-PyJWT-1.7.1-150100.6.7.1 References: https://www.suse.com/security/cve/CVE-2022-29217.html https://bugzilla.suse.com/1199756 . The latest python-PyJWT update addresses significant vulnerabilities and enhances security protocols within SUSE environments, offering detailed patch instructions for system administrators.. SUSE Python Security, Key Confusion, python-PyJWT Advisory, Security Updates, SUSE Patch Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2022 Important SuSE
89

Fedora 35 python-jwt 2022-4ae9110f51 Critical: Key Confusion Issue

Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-4ae9110f51 2022-06-01 01:25:20.629814 --------------------------------------------------------------------------------Name : python-jwt Product : Fedora 35 Version : 2.4.0 Release : 1.fc35 URL : https://github.com/jpadilla/pyjwt Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. --------------------------------------------------------------------------------Update Information: Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24 --------------------------------------------------------------------------------ChangeLog: * Thu May 19 2022 Major Hayden - 2.4.0-1 - Update to 2.4.0 (#2085157) - Fix CVE-2022-29217 (#2088546) * Tue Apr 26 2022 Carl George - 2.3.0-3 - Convert to pyproject macros * Fri Jan 21 2022 Fedora Release Engineering - 2.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Tue Oct 26 2021 Joel Capitao - 2.3.0-1 - Update to 2.3.0 (rhbz#2011642) * Sun Oct 3 2021 Kevin Fenzi - 2.1.0-3 - Relax python-cryptography requirements ( rhbz#2010061 ) --------------------------------------------------------------------------------References: [ 1 ] Bug #2085157 - python-jwt-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2085157 [ 2 ] Bug #2088546 - CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088546 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-4ae9110f51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35 Release for python-jwt resolves key ambiguity problem and strengthens security, promoting more secure JSON Web Tokens.. Fedora 35, Python JWT, Key Confusion, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 31, 2022 Critical Fedora
89

Fedora 36 python-jwt 2.4.0: Critical Key Confusion Threat Advisory

Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3cf456dc20 2022-05-27 01:08:53.900461 --------------------------------------------------------------------------------Name : python-jwt Product : Fedora 36 Version : 2.4.0 Release : 1.fc36 URL : https://github.com/jpadilla/pyjwt Summary : JSON Web Token implementation in Python Description : A Python implementation of JSON Web Token draft 01. This library provides a means of representing signed content using JSON data structures, including claims to be transferred between two parties encoded as digitally signed and encrypted JSON objects. --------------------------------------------------------------------------------Update Information: Update to 2.4.0 to address CVE-2022-29217. https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffqj-6fqr-9h24 --------------------------------------------------------------------------------ChangeLog: * Thu May 19 2022 Major Hayden - 2.4.0-1 - Update to 2.4.0 (#2085157) - Fix CVE-2022-29217 (#2088546) * Tue Apr 26 2022 Carl George - 2.3.0-3 - Convert to pyproject macros --------------------------------------------------------------------------------References: [ 1 ] Bug #2085157 - python-jwt-2.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2085157 [ 2 ] Bug #2088546 - CVE-2022-29217 python-jwt: Key confusion through non-blocklisted public key formats [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2088546 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3cf456dc20' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade to python-jwt 2.4.0 for Fedora 36 to address key confusion vulnerabilities indicated in the latest advisory.. Python JWT, Fedora Security Update, Key Confusion Risk, Security Patch, CVE Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 26, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200