TheNetworg / oauth2-azure

Azure AD provider for the OAuth 2.0 Client.
https://packagist.org/packages/thenetworg/oauth2-azure
MIT License
229 stars 108 forks source link

Firebase PHP-JWT key/algorithm type confusion #180

Closed alperendurmus closed 1 year ago

alperendurmus commented 1 year ago

Possibility of Reintroducing HS256/RSA256 Type Confusion (CVE-2021-46743) https://github.com/firebase/php-jwt/issues/351 https://github.com/advisories/GHSA-8xf4-w7qw-pjjw

alperendurmus commented 1 year ago

Looks like already compatible.