Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug]: CVE-2023-45288 github.com/go-jose/go-jose/v3 #2662

Closed
pierluigilenoci opened this issue Jun 10, 2024 · 2 comments
Closed

[Bug]: CVE-2023-45288 github.com/go-jose/go-jose/v3 #2662

pierluigilenoci opened this issue Jun 10, 2024 · 2 comments

Comments

@pierluigilenoci
Copy link
Contributor

OAuth2-Proxy Version

7.6.0

Provider

None

Expected Behaviour

Do not have any pending CVEs:
https://artifacthub.io/packages/helm/oauth2-proxy/oauth2-proxy?modal=security-report

Current Behaviour

https://artifacthub.io/packages/helm/oauth2-proxy/oauth2-proxy?modal=security-report
https://access.redhat.com/security/cve/CVE-2024-28180

Steps To Reproduce

Read the page https://artifacthub.io/packages/helm/oauth2-proxy/oauth2-proxy?modal=security-report

Possible Solutions

Upgrade the library github.com/go-jose/go-jose/v3 to v3.0.3
https://access.redhat.com/security/cve/CVE-2024-28180

Configuration details or additional information

No response

@kvanzuijlen
Copy link
Member

It's already fixed in master, and only needs a release.

@pierluigilenoci
Copy link
Contributor Author

Solved in #2663

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants