You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
okta is using python-jose library, which in turn is using ecdsa library. ecdsa package has CVE-2024-23342 and currently has no version that fixes this vuln.
is Okta planning to close this vuln, by removing ecdsa dependency for different library? thanks
The text was updated successfully, but these errors were encountered:
somurzakov-rbx
changed the title
vulnerable ecdsa package
vulnerability in indirect import of ecdsa library
Apr 3, 2024
https://security.snyk.io/vuln/SNYK-PYTHON-ECDSA-6184115
https://nvd.nist.gov/vuln/detail/CVE-2024-23342
okta is using
python-jose
library, which in turn is usingecdsa
library.ecdsa
package has CVE-2024-23342 and currently has no version that fixes this vuln.is Okta planning to close this vuln, by removing ecdsa dependency for different library? thanks
The text was updated successfully, but these errors were encountered: