jwtk / njwt

Node.js JWT support
Apache License 2.0
432 stars 49 forks source link

vulnerablity found - Out-of-bounds Read #62

Closed Toxicable closed 5 years ago

Toxicable commented 5 years ago

This package is currently maked as vulnerable see: https://www.npmjs.com/advisories/679

swiftone commented 5 years ago

We patched that in the 1.0.0 version - I'll see if we can track down why the 1.0.0 version is also listed, but the report appears erroneous.

I'll leave this issue open while I track that down, but please let me know if you know of any evidence that it's not corrected.

swiftone commented 5 years ago

They have now updated the advisory - thank you for your report!