Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-26160 create release with jwt-go v4 #46

Closed
markushinz opened this issue Mar 11, 2021 · 2 comments
Closed

CVE-2020-26160 create release with jwt-go v4 #46

markushinz opened this issue Mar 11, 2021 · 2 comments

Comments

@markushinz
Copy link

There is a CVE (CVE-2020-26160) regarding to the use of jwt-go versions prior to v4.0.0-preview1.

As the source code is already updated to use the latest version it would be nice to see a new version of ghinstallation released that does no longer rely on the vulnerable version v3.2.0.

@AlekSi
Copy link

AlekSi commented Jul 31, 2021

GitHub now complains loudly about it too: GHSA-w73w-5m7g-f7qc

@SVilgelm
Copy link

fixed by moving to golang-jwt: #53

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants