-
Notifications
You must be signed in to change notification settings - Fork 39
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Snyk:Medium] pyjwt- Use of a Broken or Risky Cryptographic Algorithm (due by 07/24/2022) #5247
Labels
Milestone
Comments
cnlucas
added
Security: moderate
Remediate within 60 days
Security: general
General security concern or issue
labels
May 25, 2022
1 task
This was referenced Jun 1, 2022
1 task
1 task
cloud-gov/django-uaa#65 |
This was referenced Jul 13, 2022
This was referenced Aug 10, 2022
1 task
@JonellaCulmer They just released the new version of cg-django-uaa, but there's still been an issue with our builds. Moving forward |
This was referenced Aug 31, 2022
1 task
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Summary
Introduced through
cg-django-uaa@2.1.3
Fixed in
pyjwt@2.4.0
Detailed paths and remediation
Overview
PyJWT is a Python implementation of RFC 7519.
Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm via non-blacklisted public key formats leading to key confusion.
Completion criteria
The text was updated successfully, but these errors were encountered: