Cryptographic issues in authlib - CVE-2024-37568
Published: June 12, 2024
Vulnerability identifier: #VU91832
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37568
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key.
Affected software
authlib
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Ubuntu
Fedora
python-authlib (Ubuntu package)
python-authlib
python311-Authlib
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Ubuntu
Fedora
python-authlib (Ubuntu package)
python-authlib
python311-Authlib
How to mitigate CVE-2024-37568
Install updates from vendor's website.
authlib - update to 1.3.1
python-authlib (Ubuntu package) - addressed in versions 0.15.5-1ubuntu0.1~esm1, 1.3.0-1ubuntu0.1~esm1
python-authlib - addressed in versions 1.3.1-1.fc39, 1.3.1-1.fc40
python311-Authlib - update to 1.3.1-150600.3.3.1
python-authlib (Ubuntu package) - addressed in versions 0.15.5-1ubuntu0.1~esm1, 1.3.0-1ubuntu0.1~esm1
python-authlib - addressed in versions 1.3.1-1.fc39, 1.3.1-1.fc40
python311-Authlib - update to 1.3.1-150600.3.3.1