- 
          
 - 
                Notifications
    
You must be signed in to change notification settings  - Fork 2.3k
 
Closed
Description
Issue Description
The golang-jwt library imported in the middleware package suffers from a CVE.
A fix is present in v5 or v5 of the library, but upgrading to v5 changes the API.
An upgrade to v4.5.1 is enough to fix the vuln.
Checklist
- Dependencies installed
 - No typos
 - Searched existing issues and docs
 
Expected behaviour
A SCA scan does not surface any vulnerabilities.
Actual behaviour
Vulnerabilty is flagged.
Version/commit
v4.12.0
Metadata
Metadata
Assignees
Labels
No labels