Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential security issue: CVE-2020-26160 #1914

Open
avoinov-k opened this issue Jul 28, 2021 · 1 comment
Open

Potential security issue: CVE-2020-26160 #1914

avoinov-k opened this issue Jul 28, 2021 · 1 comment

Comments

@avoinov-k
Copy link

Is this a BUG REPORT or FEATURE REQUEST?: BUG REPORT

What happened:
openstorage uses unmaintained package: github.com/dgrijalva/jwt-go.
There is a security vulnerability found in this library: https://nvd.nist.gov/vuln/detail/CVE-2020-26160

The recommended way to proceed is to upgrade github.com/dgrijalva/jwt-go to its maintained fork: github.com/golang-jwt/jwt which is a drop-in replacement with this issue already fixed.

@lpabon
Copy link
Member

lpabon commented Jun 28, 2022

Thank you, we will updating it to the new jwt v4.0 from github.com/golang-jwt/jwt/v4

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants