—
PYSEC-2022-259
Quick fix
PYSEC-2022-259 — python-jwt: upgrade to the fixed version with the command below.
pip install --upgrade 'python-jwt>=88ad9e67c53aa5f7c43ec4aa52ed34b7930068c9'Details
An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/python-jwt
Introduced in:
f6d1451012c6a04c2fb1940f0bbd93bb6cf2b025Fixed in: 88ad9e67c53aa5f7c43ec4aa52ed34b7930068c9Fix
pip install --upgrade 'python-jwt>=88ad9e67c53aa5f7c43ec4aa52ed34b7930068c9'