Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SOLVED: CVE-2024-23342 ecdsa may be vulnerable to the Minerva attack #178

Closed
martimors opened this issue Jan 30, 2024 · 3 comments
Closed
Assignees

Comments

@martimors
Copy link

Seems we have a dependency with a security flaw https://www.cve.org/CVERecord?id=CVE-2024-23342. Did anyone assess the risk associated with using the fastapi-azure-auth library with this dependency?

According to the maintainer it's a "wontfix" tlsfuzzer/python-ecdsa#330 (comment) so if it is unsafe we should probably switch to a non-pure python implementation of string comparisons.

@JonasKs
Copy link
Member

JonasKs commented Jan 30, 2024

We already use cryptography as the backend, and do not allow our users to configure it. There is no impact for our users of this library. The reason we get this warning is because Python-Jose allow you to configure backends, and ecdsa is one for them.

How ever, Python-Jose seems to be pretty un maintained, which raises an argument to switch to PyJWT. I'll close this issue, but this discussion can be continued if we/anyone see a need to migrate.

@JonasKs JonasKs closed this as completed Jan 30, 2024
@JonasKs
Copy link
Member

JonasKs commented Jan 30, 2024

@JonasKs JonasKs pinned this issue Feb 2, 2024
@JonasKs
Copy link
Member

JonasKs commented Feb 2, 2024

Pinning, since I keep getting emails about this.

@JonasKs JonasKs changed the title CVE-2024-23342 ecdsa may be vulnerable to the Minerva attack SOLVED: CVE-2024-23342 ecdsa may be vulnerable to the Minerva attack Feb 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants