VDB
Sign up
MEDIUM5.3

PYSEC-2024-104

Quick fix

PYSEC-2024-104 — jwcrypto: upgrade to the fixed version with the command below.

pip install --upgrade 'jwcrypto>=1.5.1'

Details

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/jwcrypto
Introduced in: 0Fixed in: 1.5.1
Fixpip install --upgrade 'jwcrypto>=1.5.1'

References