mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-02 04:20:18 +00:00
Reject JSON Web Key documents passed directly as HMAC secrets. This prevents public asymmetric JWK data from being reused as an HMAC key when an application permits mixed symmetric and asymmetric algorithms. This patch applies the relevant subset of the upstream 2.13.0 fix. The upstream commit is referenced in [1], and the public advisory is referenced in [2]. [1] https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81 [2] https://github.com/advisories/GHSA-xgmm-8j9v-c9wx Signed-off-by: Hetvi Thakar <hthakar@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
26 lines
755 B
BlitzBasic
26 lines
755 B
BlitzBasic
SUMMARY = "JSON Web Token implementation in Python"
|
|
DESCRIPTION = "A Python implementation of JSON Web Token draft 32.\
|
|
Original implementation was written by https://github.com/progrium"
|
|
HOMEPAGE = "http://github.com/jpadilla/pyjwt"
|
|
LICENSE = "MIT"
|
|
LIC_FILES_CHKSUM = "file://LICENSE;md5=e4b56d2c9973d8cf54655555be06e551"
|
|
|
|
SRC_URI += " \
|
|
file://CVE-2026-32597.patch \
|
|
file://CVE-2026-48522.patch \
|
|
file://CVE-2026-48524.patch \
|
|
file://CVE-2026-48525.patch \
|
|
file://CVE-2026-48526.patch \
|
|
"
|
|
SRC_URI[sha256sum] = "57e28d156e3d5c10088e0c68abb90bfac3df82b40a71bd0daa20c65ccd5c23de"
|
|
|
|
PYPI_PACKAGE = "PyJWT"
|
|
inherit pypi setuptools3
|
|
|
|
RDEPENDS:${PN} = " \
|
|
python3-json \
|
|
python3-cryptography \
|
|
"
|
|
|
|
BBCLASSEXTEND = "native nativesdk"
|