Skip to content

jwt-go library vulnerability CVE-2020-26160 #8336

@reimda

Description

@reimda

Security scanning turned up that telegraf uses a version of the jwt-go library that has a high severity vulnerability. It's not clear if the vulnerability can be exploited in telegraf.

Details at https://nvd.nist.gov/vuln/detail/CVE-2020-26160

jwt-go version 4.0.0-preview1 has a fix. Telegraf should update to this version or newer.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugunexpected problem or unintended behavior

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions