You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Run dependency check in a project with go-kit 0.12.0 for known vulnerabilities.
What did you expect?
Run dependency check with go-kit without vulnerabilities medium or higher.
What happened instead?
Current version of https://github.com/nats-io/jwt/v2 (v2.0.3) and github.com/nats-io/nats-server/v2 (v2.5.0) are affected by CVE-2021-3127 & CVE-2022-24450 in that this project got flagged by security scans. Both of these libs at their current version require nats-io/jwt v1.2.2 or nats-io/jwt/v2 v2.0.3 (which itself requires nats-io/jwt v1.2.2) and are both affected by CVE-2021-3127. nats-io/nats-server/v2 >= 2.7.2 patches CVE-2022-24450
The text was updated successfully, but these errors were encountered:
What did you do?
Run dependency check in a project with go-kit 0.12.0 for known vulnerabilities.
What did you expect?
Run dependency check with go-kit without vulnerabilities medium or higher.
What happened instead?
Current version of
https://github.com/nats-io/jwt/v2
(v2.0.3) andgithub.heygears.com/nats-io/nats-server/v2
(v2.5.0) are affected byCVE-2021-3127
&CVE-2022-24450
in that this project got flagged by security scans. Both of these libs at their current version requirenats-io/jwt v1.2.2
ornats-io/jwt/v2 v2.0.3
(which itself requiresnats-io/jwt v1.2.2
) and are both affected byCVE-2021-3127
.nats-io/nats-server/v2
>= 2.7.2 patchesCVE-2022-24450
The text was updated successfully, but these errors were encountered: