Vulnerability Bulletins

DSA-3979 pyjwt - security update

   
Affected software Debian
 
It was discovered that PyJWT, a Python implementation of JSON Web Tokenperformed insufficient validation of some public key types, which couldallow a remote attacker to craft JWTs from scratch.

More info:

https://www.debian.org/security/2017/dsa-3979