Closed
Description
Issue Description
The golang-jwt
library imported in the middleware
package suffers from a CVE.
A fix is present in v5 or v5 of the library, but upgrading to v5 changes the API.
An upgrade to v4.5.1 is enough to fix the vuln.
Checklist
- Dependencies installed
- No typos
- Searched existing issues and docs
Expected behaviour
A SCA scan does not surface any vulnerabilities.
Actual behaviour
Vulnerabilty is flagged.
Version/commit
v4.12.0
Metadata
Metadata
Assignees
Labels
No labels