Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reporting a vulnerability #2

Closed
TomTervoort opened this issue Aug 31, 2022 · 4 comments
Closed

Reporting a vulnerability #2

TomTervoort opened this issue Aug 31, 2022 · 4 comments

Comments

@TomTervoort
Copy link

Hi,

I discovered a vulnerability in JWX that I would like to report. However, I can't seem to find an appropriate (private) channel to contact the maintainer for responsible disclosure.

@sop How would you like to receive this report?

@sop
Copy link
Owner

sop commented Aug 31, 2022

Hi!

I've added email address to my profile.

@TomTervoort
Copy link
Author

Thanks! I'll reach out to you via mail.

@kenjis
Copy link

kenjis commented Apr 17, 2023

Hi, this vulnerability was fixed or not?

@sop
Copy link
Owner

sop commented Apr 17, 2023

Hi, this vulnerability was fixed or not?

Hi! It was fixed in master branch but i never got to push a release. I've just released a new tag, which is a major release by semantic versioning, so please update your dependencies if necessary. Technically this is a breaking change if someone was relying on vulnerable algorithms in question.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants