-
Notifications
You must be signed in to change notification settings - Fork 401
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2020-9283 #367
Comments
go-jose does not appear to have a tagged release, so I'll probably wait for them to do that first https://github.com/go-jose/go-jose/releases I also don't see how this package could be impacted by an SSH server panic. |
The latest minor release for go-jose v3 was published three days ago. |
Should be fixed by #399 which is in the latest release. Thanks! https://github.com/coreos/go-oidc/releases/tag/v3.9.0 |
I think, we need to bump to 3.0.3 to get "Limit decompression output size to prevent a DoS. Backport from v4.0.1.". @ericchiang do you want me to manually bump it or dependabot will take care?. |
any chance that we can resolve this? https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9283
go-jose/go-jose#31
upgrading go-jose could help.
The text was updated successfully, but these errors were encountered: