Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

JWX vulnerable to a denial of service attack using compressed JWE message #51647

Closed
hawkingrei opened this issue Mar 11, 2024 · 0 comments · Fixed by #51648
Closed

JWX vulnerable to a denial of service attack using compressed JWE message #51647

hawkingrei opened this issue Mar 11, 2024 · 0 comments · Fixed by #51648
Labels
severity/moderate sig/sql-infra SIG: SQL Infra type/bug This issue is a bug.

Comments

@hawkingrei
Copy link
Member

Bug Report

Please answer these questions before submitting your issue. Thanks!

1. Minimal reproduce step (Required)

image

https://github.com/pingcap/tidb/security/dependabot/73

2. What did you expect to see? (Required)

3. What did you see instead (Required)

4. What is your TiDB version? (Required)

@hawkingrei hawkingrei added type/bug This issue is a bug. sig/sql-infra SIG: SQL Infra severity/moderate labels Mar 11, 2024
ti-chi-bot bot pushed a commit that referenced this issue Mar 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
severity/moderate sig/sql-infra SIG: SQL Infra type/bug This issue is a bug.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant