Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.0.0.RC1 nimbus-jose-jwt-4.36 CVE-2019-17195 #486

Closed
robertoschwald opened this issue Nov 20, 2020 · 1 comment
Closed

2.0.0.RC1 nimbus-jose-jwt-4.36 CVE-2019-17195 #486

robertoschwald opened this issue Nov 20, 2020 · 1 comment

Comments

@robertoschwald
Copy link

CVE-2019-17195:
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

Dependabot already added PR #483 to upgrade develop branch to Nimbus JOSE+JWT 9.1.2, but I'm not sure if that one works with the 2.x branch as well.

@jdaugherty
Copy link
Contributor

This CVE is resolved by the upgrades in #521

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants