Use of a broken or risky cryptographic algorithm in pyjwt - CVE-2022-29217
Published: May 13, 2022
Vulnerability identifier: #VU63168
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29217
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to use of a broken or risky cryptographic algorithm. A remote attacker can cause key confusion through non-blocklisted public key formats.
Affected software
pyjwt
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Fusion HCI
Spectrum Discover
IBM Watson Discovery for IBM Cloud Pak for Data
SUSE Linux Enterprise Module for Packagehub Subpackages
python-jwt (Ubuntu package)
python3-jwt (Ubuntu package)
python3-PyJWT
python-PyJWT
python-jwt-help
python3-jwt
python-jwt
python2-jwt
python2-PyJWT
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
IBM Fusion HCI
Spectrum Discover
IBM Watson Discovery for IBM Cloud Pak for Data
SUSE Linux Enterprise Module for Packagehub Subpackages
python-jwt (Ubuntu package)
python3-jwt (Ubuntu package)
python3-PyJWT
python-PyJWT
python-jwt-help
python3-jwt
python-jwt
python2-jwt
python2-PyJWT
How to mitigate CVE-2022-29217
Install updates from vendor's website.
pyjwt - update to 2.4.0
IBM Fusion HCI - update to 2.10.0
python-jwt (Ubuntu package) - update to 1.5.3+ds1-1ubuntu0.1
python3-jwt (Ubuntu package) - addressed in versions 1.5.3+ds1-1ubuntu0.1, 1.7.1-2ubuntu2.1, 2.3.0-1ubuntu0.1
python3-PyJWT - addressed in versions 1.5.3-3.16.1, 1.5.3-150000.3.3.1, 1.7.1-150100.6.7.1, 1.7.1-150200.3.3.1, 2.4.0-150200.3.6.2
python-PyJWT - update to 1.5.3-3.16.1
python-jwt-help - update to 1.7.1-3
python3-jwt - update to 1.7.1-3
python-jwt - update to 1.7.1-3
python2-jwt - update to 1.7.1-3
python2-PyJWT - addressed in versions 1.7.1-150100.6.7.1, 1.7.1-150200.3.3.1
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
python-jwt - update to 2.4.0-1
python-jwt - addressed in versions 2.4.0-1.el9, 2.4.0-1.fc35, 2.4.0-1.fc36
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.1
IBM Fusion HCI - update to 2.10.0
python-jwt (Ubuntu package) - update to 1.5.3+ds1-1ubuntu0.1
python3-jwt (Ubuntu package) - addressed in versions 1.5.3+ds1-1ubuntu0.1, 1.7.1-2ubuntu2.1, 2.3.0-1ubuntu0.1
python3-PyJWT - addressed in versions 1.5.3-3.16.1, 1.5.3-150000.3.3.1, 1.7.1-150100.6.7.1, 1.7.1-150200.3.3.1, 2.4.0-150200.3.6.2
python-PyJWT - update to 1.5.3-3.16.1
python-jwt-help - update to 1.7.1-3
python3-jwt - update to 1.7.1-3
python-jwt - update to 1.7.1-3
python2-jwt - update to 1.7.1-3
python2-PyJWT - addressed in versions 1.7.1-150100.6.7.1, 1.7.1-150200.3.3.1
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
python-jwt - update to 2.4.0-1
python-jwt - addressed in versions 2.4.0-1.el9, 2.4.0-1.fc35, 2.4.0-1.fc36
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.1
External References
Related Security Bulletins
- Use of a broken or risky cryptographic algorithm in pyjwt
- SUSE update for python-PyJWT
- SUSE update for python-PyJWT
- SUSE update for python-PyJWT
- Ubuntu update for pyjwt
- Use of a broken or risky cryptographic algorithm in IBM Watson Discovery for IBM Cloud Pak for Data
- SUSE update for python-PyJWT
- SUSE update for python-PyJWT
- Multiple vulnerabilities in IBM Spectrum Discover
- openEuler update for python-jwt
- Amazon Linux AMI update for python-jwt
- Fedora 35 update for python-jwt
- Fedora EPEL 9 update for python-jwt
- Fedora 36 update for python-jwt
- Multiple vulnerabilities in IBM Fusion