Skip to content

jwt-go library vulnerability #997

@foolmacky

Description

@foolmacky

Hello,

I'm using viper in our project in my company.
Recently, critical vulnerability has detected by 'Source Clear',
and I can't release updates.

The cause of this vulnerability is jwt-go library.
https://www.sourceclear.com/vulnerability-database/security/authorization-bypass/go/sid-27284

In jwt-go project the vulnerability is indicated on July, 2020.
But there is no action ?, and the issue was closed.
And some of users move away from unmaintained jwt-go project.
Sigh...

dgrijalva/jwt-go#422
dgrijalva/jwt-go#426
go-chi/jwtauth#50

Please let me know how you handle this matter in viper ?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions