Safety vulnerability ID: 35682
The information on this page was manually curated by our Cybersecurity Intelligence Team.
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
Latest version: 3.3.0
JOSE implementation in Python
python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
CONFIRM:https://github.com/mpdavis/python-jose/pull/35/commits/89b46353b9f611e9da38de3d2fedf52331167b93: https://github.com/mpdavis/python-jose/pull/35/commits/89b46353b9f611e9da38de3d2fedf52331167b93
CONFIRM:https://github.com/mpdavis/python-jose/releases/tag/1.3.2: https://github.com/mpdavis/python-jose/releases/tag/1.3.2
BID:95845: http://www.securityfocus.com/bid/95845
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application