Skip to content
This repository was archived by the owner on Jul 7, 2025. It is now read-only.

Update vulnerable dependencies#57

Closed
kidd0123 wants to merge 1 commit intotibdex:mainfrom
kidd0123:main
Closed

Update vulnerable dependencies#57
kidd0123 wants to merge 1 commit intotibdex:mainfrom
kidd0123:main

Conversation

@kidd0123
Copy link
Copy Markdown

Snyk has found a vulnerability in one of your dependency. This was patched in a minor version update on @octokit/auth-app v4.0.8.

@kj4ezj
Copy link
Copy Markdown

kj4ezj commented Jan 25, 2023

I accidentally duplicated your work here in pull request 61 and pull request 62 from dependabot alerts on my fork...my bad. I didn't mean to waste my time or to step on your toes. I closed 61, but 62 is a slightly newer patch version and I don't understand the differences so I'll leave that one.

@kj4ezj
Copy link
Copy Markdown

kj4ezj commented Jan 25, 2023

CVEs addressed by this pull request:

  • CVE-2022-23529 - jsonwebtoken has insecure input validation in jwt.verify function
  • CVE-2022-23539 - jsonwebtoken unrestricted key type could lead to legacy keys usage
  • CVE-2022-23540 - jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
  • CVE-2022-23541 - jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
  • CVE-2022-46175 - Prototype Pollution in JSON5 via Parse Method

@tibdex tibdex mentioned this pull request Jan 26, 2023
@tibdex tibdex closed this in #64 Jan 26, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants