Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

x/vulndb: potential Go vuln in github.com/MicahParks/jwkset: CVE-2025-22149 #3378

Closed
GoVulnBot opened this issue Jan 9, 2025 · 1 comment

Comments

@GoVulnBot
Copy link

Advisory CVE-2025-22149 references a vulnerability in the following Go modules:

Module
github.com/MicahParks/jwkset

Description:
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite or append. This is a security issue for use cases that utilize the provided auto-caching HTTP client and where key removal from a JWK Set is equivalent to revocation. The affected auto-caching HTTP client was added in version v0.5.0 and fixed in v0.6.0. The only workaround would be to remove the provided auto-caching HTTP client and replace it...

References:

No existing reports found with this module or alias.
See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/MicahParks/jwkset
      vulnerable_at: 0.6.0
summary: CVE-2025-22149 in github.com/MicahParks/jwkset
cves:
    - CVE-2025-22149
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-22149
    - fix: https://github.com/MicahParks/jwkset/commit/01db49a90f7f20c7fb39a699a2f19a7a5f379ed3
    - report: https://github.com/MicahParks/jwkset/issues/40
    - web: https://github.com/MicahParks/jwkset/security/advisories/GHSA-675f-rq2r-jw82
source:
    id: CVE-2025-22149
    created: 2025-01-09T19:01:20.798985277Z
review_status: UNREVIEWED

@tatianab
Copy link
Contributor

tatianab commented Jan 9, 2025

Duplicate of #3376

@tatianab tatianab marked this as a duplicate of #3376 Jan 9, 2025
@tatianab tatianab closed this as completed Jan 9, 2025
# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

2 participants