saml icon indicating copy to clipboard operation
saml copied to clipboard

Address GO-2024-3250 vulnerability

Open floren opened this issue 1 year ago • 1 comments

https://pkg.go.dev/vuln/GO-2024-3250

Addressed by bumping the github.com/golang-jwt/jwt/v4 library from v4.5.0 to v4.5.1.

Based on a quick look at the calls to ParseWithClaims (the affected function) I don't think there was necessarily a problem to begin with (we treated all errors as fatal), but this will make go vuln happy which is important.

floren avatar Nov 12 '24 18:11 floren

I don't quite understand what's going on with the linter here.

floren avatar Nov 12 '24 18:11 floren

fixed in #592

crewjam avatar Apr 12 '25 10:04 crewjam