Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

2.0.1 - Security Fix #96

Discussion options

What's Changed

Disclosure date

2023年03月07日T18:48:04.077Z

Title

Vulnerable python_jwt dependecy version used, leading to CVE-2022-39227

Severity

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N = Critical (10)

Vulnerability Type

Authentication Bypass by Spoofing

Thanks to @notnci for locating & @psmoros for reporting.

Full Changelog: 2.0.0...2.0.1


This discussion was created from the release 2.0.1 - Security Fix.
You must be logged in to vote

Replies: 0 comments

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant

AltStyle によって変換されたページ (->オリジナル) /