bcgov / nr-forest-client

FSA Forest Client
Apache License 2.0
3 stars 1 forks source link

Fix code scanning alert - Denial of Service in Connect2id Nimbus JOSE+JWT #885

Closed paulushcgcj closed 6 months ago

paulushcgcj commented 8 months ago

Tracking issue for:

paulushcgcj commented 8 months ago

So far, a fix for this issue is not available. the dependency library used (Nimbus JOSE+JWT)[https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt] is still reporting not only this but another CVE associated to some of it's dependencies yet. We will keep monitoring it for any possible mitigation scenario available.