메뉴 건너뛰기

GREATUSER

cve

CVE-2017-11424

관리자 2017.08.27 07:00 조회 수 : 7

In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA PUBLIC KEY-----` which is not accounted for. This enables symmetric/asymmetric key confusion attacks against users using the PKCS1 PEM encoded public keys, which would allow an attacker to craft JWTs from scratch.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-11424
번호 제목 글쓴이 날짜 조회 수
572 CVE-2017-0026 관리자 2017.03.18 0
571 CVE-2017-0040 관리자 2017.03.18 0
570 CVE-2017-0066 관리자 2017.03.18 0
569 CVE-2017-0069 관리자 2017.03.18 0
568 CVE-2017-0096 관리자 2017.03.18 0
567 CVE-2017-0030 관리자 2017.03.18 1
566 CVE-2017-0039 관리자 2017.03.18 1
565 CVE-2017-0043 관리자 2017.03.18 1
564 CVE-2017-0094 관리자 2017.03.18 1
563 CVE-2017-0095 관리자 2017.03.18 1
562 CVE-2017-0084 관리자 2017.03.18 1
561 CVE-2017-0086 관리자 2017.03.18 1
560 CVE-2016-3203 관리자 2016.06.17 2
559 CVE-2017-0088 관리자 2017.03.18 2
558 CVE-2015-5224 관리자 2017.08.27 2
위로