CVE-2024-28102

medium
Published 2024-04-30 ยท Modified 2024-05-22
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2024:3267: idm:DL1 and idm:client security update (Moderate)

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description python-jwcrypto: malicious JWE token can cause denial of service Red Hat statement The CVE-2024-28102 vulnerability in JWCrypto represents a moderate severity issue due to its potential impact on system availability and resource consumption. While the vulnerability allows for a denial of service (DoS) attack, it requires an attacker to craft a malicious JWE Token with a highโ€ฆ

Description

python-jwcrypto: malicious JWE token can cause denial of service

Red Hat statement

The CVE-2024-28102 vulnerability in JWCrypto represents a moderate severity issue due to its potential impact on system availability and resource consumption. While the vulnerability allows for a denial of service (DoS) attack, it requires an attacker to craft a malicious JWE Token with a high compression ratio. This specific condition limits the practical exploitability of the vulnerability to some extent, as it demands a more sophisticated attack approach than common vulnerabilities. Nonetheless, if exploited, the vulnerability can lead to significant memory exhaustion and increased server processing time, impacting the overall performance and availability of the affected system.

CVSS v3: 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Ansible Automation Platform 2.4 for RHEL 8automation-controller-0:4.5.8-1.el8apRHSA-2024:45222024-07-12T00:00:00Z
Red Hat Ansible Automation Platform 2.4 for RHEL 9automation-controller-0:4.5.8-1.el9apRHSA-2024:45222024-07-12T00:00:00Z
Red Hat Enterprise Linux 8idm:client-8100020240417004735.143e9e98RHSA-2024:32672024-05-22T00:00:00Z
Red Hat Enterprise Linux 8idm:DL1-8100020240416171943.823393f5RHSA-2024:32672024-05-22T00:00:00Z
Red Hat Enterprise Linux 9python-jwcrypto-0:0.8-5.el9_4RHSA-2024:25592024-04-30T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 7python-jwcryptoOut of support scope

Apply commands

bash fix
Apply RHSA-2024:4522 for Red Hat Ansible Automation Platform 2.4 for RHEL 8
yum update -y automation-controller
# or:
dnf upgrade -y automation-controller

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.5.6-1
sid Fixed 1.5.6-1
forky Fixed 1.5.6-1
bullseye Fixed 0.8.0-1+deb11u1
bookworm Fixed 1.1.0-1+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIjwcrypto<1.5.61.5.6

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.