mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-02 16:30:22 +00:00
Reject a non-empty compact payload segment for b64=false tokens before Base64URL decoding. The segment is unused for detached JWS verification, so decoding it allowed unauthenticated CPU and memory consumption. This patch applies the relevant subset of the upstream 2.13.0 fix. The upstream commit is referenced in [1], and the public advisory is referenced in [2]. [1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 [2] https://github.com/advisories/GHSA-w7vc-732c-9m39 Signed-off-by: Hetvi Thakar <hthakar@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
25 lines
721 B
BlitzBasic
25 lines
721 B
BlitzBasic
SUMMARY = "JSON Web Token implementation in Python"
|
|
DESCRIPTION = "A Python implementation of JSON Web Token draft 32.\
|
|
Original implementation was written by https://github.com/progrium"
|
|
HOMEPAGE = "http://github.com/jpadilla/pyjwt"
|
|
LICENSE = "MIT"
|
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=e4b56d2c9973d8cf54655555be06e551"
|
|
|
|
SRC_URI += " \
|
|
file://CVE-2026-32597.patch \
|
|
file://CVE-2026-48522.patch \
|
|
file://CVE-2026-48524.patch \
|
|
file://CVE-2026-48525.patch \
|
|
"
|
|
SRC_URI[sha256sum] = "57e28d156e3d5c10088e0c68abb90bfac3df82b40a71bd0daa20c65ccd5c23de"
|
|
|
|
PYPI_PACKAGE = "PyJWT"
|
|
inherit pypi setuptools3
|
|
|
|
RDEPENDS:${PN} = " \
|
|
python3-json \
|
|
python3-cryptography \
|
|
"
|
|
|
|
BBCLASSEXTEND = "native nativesdk"
|