Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The dependency jwt-go v3.2.0 has security issues, need to update to latest version v4.0.0-preview1 #11

Closed
zmaxyan opened this issue Nov 2, 2020 · 3 comments

Comments

@zmaxyan
Copy link

zmaxyan commented Nov 2, 2020

CVE-2020-26160
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails, "" is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.

@jdolitsky
Copy link
Contributor

thank you!

@jdolitsky
Copy link
Contributor

We updated to latest commit in the repository - if there is an error, could you help with PR?

@zmaxyan
Copy link
Author

zmaxyan commented Jun 22, 2021

Hi guys the version you give jwt-go is "github.com/dgrijalva/jwt-go / 3.2.1-0.20200107013213-dc14462fd587+incompatible", there is a release version which is "v4.0.0-preview1", can you change the version "3.2.1-0.20200107013213-dc14462fd587" using this release version?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants