{"id":"SUSE-SU-2021:2010-1","summary":"Security update for python-PyJWT","details":"This update for python-PyJWT fixes the following issues:\n\npython-JWT was updated to 1.5.3. (bsc#1186173)\n\nupdate to version 1.5.3:\n\n  * Changed\n\n    + Increase required version of the cryptography package to\n      \u003e=1.4.0.\n\n  * Fixed\n\n    + Remove uses of deprecated functions from the cryptography\n      package.\n    + Warn about missing algorithms param to decode() only when verify\n      param is True #281\n\n\nupdate to version 1.5.2:\n\n- Ensure correct arguments order in decode super call [7c1e61d][7c1e61d]\n- Change optparse for argparse. [#238][238]\n- Guard against PKCS1 PEM encododed public keys [#277][277]\n- Add deprecation warning when decoding without specifying `algorithms` [#277][277]\n- Improve deprecation messages [#270][270]\n- PyJWT.decode: move verify param into options [#271][271]\n- Support for Python 3.6 [#262][262]\n- Expose jwt.InvalidAlgorithmError [#264][264]\n- Add support for ECDSA public keys in RFC 4253 (OpenSSH) format [#244][244]\n- Renamed commandline script `jwt` to `jwt-cli` to avoid issues with the script clobbering the `jwt` module in some circumstances. [#187][187]\n- Better error messages when using an algorithm that requires the cryptography package, but it isn't available [#230][230]\n- Tokens with future 'iat' values are no longer rejected [#190][190]\n- Non-numeric 'iat' values now raise InvalidIssuedAtError instead of DecodeError\n- Remove rejection of future 'iat' claims [#252][252]\n- Add back 'ES512' for backward compatibility (for now) [#225][225]\n- Fix incorrectly named ECDSA algorithm [#219][219]\n- Fix rpm build [#196][196]\n- Add JWK support for HMAC and RSA keys [#202][202]\n\n","modified":"2026-02-04T04:34:08.551817Z","published":"2021-06-18T07:03:27Z","related":["CVE-2017-12880"],"upstream":["CVE-2017-12880"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20212010-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1186173"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12880"}],"affected":[{"package":{"name":"python-PyJWT","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/python-PyJWT&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-3.13.1"}]}],"ecosystem_specific":{"binaries":[{"python-PyJWT":"1.5.3-3.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2010-1.json"}},{"package":{"name":"python-PyJWT","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 12","purl":"pkg:rpm/suse/python-PyJWT&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.3-3.13.1"}]}],"ecosystem_specific":{"binaries":[{"python-PyJWT":"1.5.3-3.13.1","python3-PyJWT":"1.5.3-3.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:2010-1.json"}}],"schema_version":"1.7.3"}