firebase / php-jwt

PHP package for JWT
BSD 3-Clause "New" or "Revised" License
9.38k stars 1.27k forks source link

Firebase PHP-JWT Key/Algorithm Type Confusion #557

Closed ankitdn closed 3 months ago

ankitdn commented 8 months ago

Describe the bug While scanning my Laravel application's manifest file using Vulert for vulnerability checks, I identified an issue associated with your package.

Reference Upon conducting a vulnerability scan, the following references were identified: Vulert Scan Report: Vulert Report CVE Reference: CVE-2021-46743

bshaffer commented 3 months ago

This has been fixed in v6 of this library for a very long time. It's possible you are running an older version of this library.

See the v6.0 release for instructions on how to upgrade.