Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update vulnerable dependencies #57

Closed
wants to merge 1 commit into from
Closed

Conversation

kidd0123
Copy link

Snyk has found a vulnerability in one of your dependency. This was patched in a minor version update on @octokit/auth-app v4.0.8.

@kj4ezj
Copy link

kj4ezj commented Jan 25, 2023

I accidentally duplicated your work here in pull request 61 and pull request 62 from dependabot alerts on my fork...my bad. I didn't mean to waste my time or to step on your toes. I closed 61, but 62 is a slightly newer patch version and I don't understand the differences so I'll leave that one.

@kj4ezj
Copy link

kj4ezj commented Jan 25, 2023

CVEs addressed by this pull request:

  • CVE-2022-23529 - jsonwebtoken has insecure input validation in jwt.verify function
  • CVE-2022-23539 - jsonwebtoken unrestricted key type could lead to legacy keys usage
  • CVE-2022-23540 - jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
  • CVE-2022-23541 - jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
  • CVE-2022-46175 - Prototype Pollution in JSON5 via Parse Method

@tibdex tibdex mentioned this pull request Jan 26, 2023
@tibdex tibdex closed this in #64 Jan 26, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants